ESB URL Extension Security & Risk Analysis

wordpress.org/plugins/esb-url-extension

This plugin will allow you to add extensions to WordPress url as per your preference.

100 active installs v1.0.0 PHP + WP 3.5+ Updated Dec 24, 2014
aspconvertingextextensionextensions
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ESB URL Extension Safe to Use in 2026?

Generally Safe

Score 85/100

ESB URL Extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'esb-url-extension' plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The complete absence of known CVEs and a clean vulnerability history are positive indicators. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations or external HTTP requests. However, the lack of any explicit capability checks, nonce checks, or permission callbacks on its entry points, while currently presenting zero unprotected entry points, raises a significant concern. This indicates a reliance on external mechanisms or a potentially underdeveloped security layer for its handlers, which could become a risk if the attack surface grows or if the plugin's functionality evolves without corresponding security enhancements.

While the current static analysis shows no critical or high-severity issues like dangerous functions or unsanitized taint flows, the 50% rate of improperly escaped output is a notable weakness. This could lead to cross-site scripting (XSS) vulnerabilities if the unsanitized data is ever displayed to users in a context where it can be interpreted as code. The absence of any identified attack surface entry points is promising, but the lack of built-in authentication or authorization checks for the limited code signals is a potential oversight that warrants attention for future development.

Key Concerns

  • Output escaping is not consistently applied
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

ESB URL Extension Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ESB URL Extension Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

ESB URL Extension Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitesb-url-extension.php:41
actionadmin_menuincludes\admin\esb-eu-admin.php:71
actionadmin_initincludes\admin\esb-eu-admin.php:74
filterplugin_action_linksincludes\admin\esb-eu-admin.php:77
filterscript_loader_srcincludes\esb-eu-public.php:17
filterstyle_loader_srcincludes\esb-eu-public.php:18
filterclean_urlincludes\esb-eu-public.php:28
actioninitincludes\esb-eu-public.php:47
filteruser_trailingslashitincludes\esb-eu-public.php:57
actionadmin_enqueue_scriptsincludes\esb-eu-scripts.php:22
Maintenance & Trust

ESB URL Extension Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedDec 24, 2014
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

ESB URL Extension Developer Profile

eSparkBiz

3 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ESB URL Extension

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/esb-url-extension/css/admin-style.css
Version Parameters
esb-url-extension/css/admin-style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ESB URL Extension