eRocket Security & Risk Analysis

wordpress.org/plugins/erocket

Supercharge your WordPress themes with extra functionalities and modules.

300 active installs v1.2.5 PHP 7.0+ WP 5.9+ Updated May 11, 2023
templatethemethemeswidgetwidgets
85
A · Safe
CVEs total1
Unpatched0
Last CVEApr 21, 2023
Safety Verdict

Is eRocket Safe to Use in 2026?

Generally Safe

Score 85/100

eRocket has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 21, 2023Updated 2yr ago
Risk Assessment

The 'erocket' plugin v1.2.5 exhibits a mixed security posture. On one hand, the static analysis shows a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries utilize prepared statements, which is a significant strength in preventing SQL injection vulnerabilities. The presence of a nonce check and file operations, while present, are not inherently problematic without further context.

However, the 57% proper output escaping rate is a notable concern. This indicates that a significant portion of data outputted by the plugin may be vulnerable to Cross-Site Scripting (XSS) attacks. While no critical or high severity taint flows were detected in the static analysis, the historical vulnerability data reveals a past medium severity XSS vulnerability. The recurring nature of XSS as a common vulnerability type, coupled with the imperfect output escaping, suggests a potential for similar issues to arise.

In conclusion, while 'erocket' v1.2.5 has strengths in its limited attack surface and secure SQL handling, the suboptimal output escaping and historical XSS vulnerability necessitate caution. The plugin needs to prioritize addressing the output escaping issues to mitigate the risk of XSS.

Key Concerns

  • Improper output escaping rate is concerning
  • History of XSS vulnerabilities
Vulnerabilities
1

eRocket Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-28174medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

eRocket <= 1.2.4 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 21, 2023 Patched in 1.2.5 (277d)
Code Analysis
Analyzed Mar 16, 2026

eRocket Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
50
65 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

57% escaped115 total outputs
Attack Surface

eRocket Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitsrc\FeaturedPosts.php:10
actioncustomize_registersrc\FeaturedPosts.php:26
actionwidgets_initsrc\Loader.php:8
actionadmin_menusrc\Sharing.php:46
filterthe_contentsrc\Sharing.php:47
actionerocket_sharing_ouputsrc\Sharing.php:48
actionwp_headsrc\Widgets\ContactInfo.php:37
actionwp_headsrc\Widgets\RecentPosts.php:25
Maintenance & Trust

eRocket Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMay 11, 2023
PHP min version7.0
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

eRocket Developer Profile

Anh Tran

17 plugins · 85K total installs

85
trust score
Avg Security Score
96/100
Avg Patch Time
76 days
View full developer profile
Detection Fingerprints

How We Detect eRocket

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/erocket/admin/css/select2.min.css/wp-content/plugins/erocket/admin/css/select2-theme-bootstrap.min.css/wp-content/plugins/erocket/admin/js/select2.min.js/wp-content/plugins/erocket/admin/js/erocket-admin.js/wp-content/plugins/erocket/public/css/erocket-public.css/wp-content/plugins/erocket/public/js/erocket-public.js
Script Paths
/wp-content/plugins/erocket/admin/js/select2.min.js/wp-content/plugins/erocket/admin/js/erocket-admin.js/wp-content/plugins/erocket/public/js/erocket-public.js

HTML / DOM Fingerprints

CSS Classes
ecieci-infoeci-profileserperp-verticalerp-horizontalerp-body
HTML Comments
<!-- wp:social-links --><!-- /wp:social-links --><!-- wp:social-link /-->+26 more
Data Attributes
data-erocket-search
JS Globals
ERocket
Shortcode Output
[erocket_subscribe_form][erocket_recent_posts][erocket_comments][erocket_about_widget]
FAQ

Frequently Asked Questions about eRocket