ElPlan Kuchikomi Wall Security & Risk Analysis

wordpress.org/plugins/elplan-kuchikomi-wall

Display Google Business Profile reviews on your site. Pro: your business appears with ★ star ratings in Google Search results — boosting local SEO and …

0 active installs v2.0.6 PHP 7.4+ WP 6.0+ Updated Mar 29, 2026
business-reviewsgoogle-reviewslocal-seoschema-orgstructured-data
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ElPlan Kuchikomi Wall Safe to Use in 2026?

Generally Safe

Score 100/100

ElPlan Kuchikomi Wall has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The elplan-kuchikomi-wall plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin utilizes prepared statements for all SQL queries and has a very high percentage of properly escaped output, which are crucial security best practices. The presence of numerous nonce and capability checks further strengthens its defenses against common attack vectors. Its attack surface, though featuring several AJAX handlers, is fully protected with authentication checks, and there are no unauthenticated REST API routes or cron events to exploit.

However, a single flow with an unsanitized path identified during taint analysis is a notable concern. While rated as not critical or high severity, such flows can still lead to vulnerabilities like path traversal if not properly handled. The plugin also makes external HTTP requests, which, while not inherently insecure, can become a vector if the target endpoints are compromised or if sensitive data is sent without proper encryption. The bundled Freemius library, if outdated, could also introduce risks, although its specific version (v1.0) is not immediately indicative of a problem without further context on known vulnerabilities for that version.

Given the lack of any recorded vulnerabilities (CVEs) and the robust implementation of secure coding practices observed in the static analysis, the overall risk profile appears low. The plugin demonstrates a commitment to security by employing secure database operations and output handling. The primary area for attention is the identified unsanitized path flow, which warrants investigation and remediation to ensure complete security.

Key Concerns

  • Flow with unsanitized path identified
  • Bundled library (Freemius v1.0) may be outdated
Vulnerabilities
None known

ElPlan Kuchikomi Wall Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ElPlan Kuchikomi Wall Release Timeline

v2.0.6Current
v2.0.5
v2.0.4
v2.0.3
v2.0.2
Code Analysis
Analyzed Apr 16, 2026

ElPlan Kuchikomi Wall Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
19 prepared
Unescaped Output
5
505 escaped
Nonce Checks
16
Capability Checks
6
File Operations
0
External Requests
5
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared19 total queries

Output Escaping

99% escaped510 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

6 flows1 with unsanitized paths
handle_actions (includes/class-tmnl-admin.php:103)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ElPlan Kuchikomi Wall Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 3

authwp_ajax_tmnl_test_api_keyincludes/class-tmnl-admin.php:12
authwp_ajax_tmnl_download_qrincludes/class-tmnl-qr.php:29
authwp_ajax_tmnl_fetch_x_urlincludes/class-tmnl-sns-collector.php:17

Shortcodes 2

[tmnl_kuchikomi_wall] includes/class-tmnl-shortcode.php:23
[tmnl_testimonials] includes/class-tmnl-shortcode.php:24
WordPress Hooks 12
actioninitelplan-kuchikomi-wall.php:54
actionadmin_initelplan-kuchikomi-wall.php:100
actionadmin_menuincludes/class-tmnl-admin.php:9
actionadmin_initincludes/class-tmnl-admin.php:10
actionadmin_enqueue_scriptsincludes/class-tmnl-admin.php:11
actioninitincludes/class-tmnl-block.php:17
filtercron_schedulesincludes/class-tmnl-cron.php:20
actionwp_headincludes/class-tmnl-jsonld.php:27
actiontmnl_dashboard_after_sectionsincludes/class-tmnl-qr.php:26
actionwp_enqueue_scriptsincludes/class-tmnl-shortcode.php:25
actionadmin_menuincludes/class-tmnl-sns-collector.php:15
actionadmin_initincludes/class-tmnl-sns-collector.php:16
Maintenance & Trust

ElPlan Kuchikomi Wall Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 29, 2026
PHP min version7.4
Downloads137

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ElPlan Kuchikomi Wall Developer Profile

PixelPlanet

3 plugins · 70 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ElPlan Kuchikomi Wall

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elplan-kuchikomi-wall/assets/css/tmnl-card.css/wp-content/plugins/elplan-kuchikomi-wall/assets/css/tmnl-list.css/wp-content/plugins/elplan-kuchikomi-wall/assets/css/tmnl-slider.css/wp-content/plugins/elplan-kuchikomi-wall/assets/icons/icon-m1.png/wp-content/plugins/elplan-kuchikomi-wall/assets/icons/icon-m2.png/wp-content/plugins/elplan-kuchikomi-wall/assets/icons/icon-m3.png/wp-content/plugins/elplan-kuchikomi-wall/assets/icons/icon-w1.png/wp-content/plugins/elplan-kuchikomi-wall/assets/icons/icon-w2.png+2 more
Script Paths
/wp-content/plugins/elplan-kuchikomi-wall/assets/js/tmnl-slider.js
Version Parameters
elplan-kuchikomi-wall/assets/css/tmnl-card.css?ver=elplan-kuchikomi-wall/assets/css/tmnl-list.css?ver=elplan-kuchikomi-wall/assets/css/tmnl-slider.css?ver=elplan-kuchikomi-wall/assets/js/tmnl-slider.js?ver=

HTML / DOM Fingerprints

CSS Classes
tmnl-testimonial-cardtmnl-testimonial-listtmnl-testimonial-slider
HTML Comments
<!-- testimonial card --><!-- testimonial list --><!-- testimonial slider -->
Data Attributes
data-templatedata-columnsdata-colordata-min-ratingdata-sourcedata-limit
JS Globals
tmnl_slider_params
Shortcode Output
[tmnl_kuchikomi_wall][tmnl_testimonials]
FAQ

Frequently Asked Questions about ElPlan Kuchikomi Wall