
Expenses Book Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/expenses-bookYou want to record your expenses history in a 100% private and 100% safe place? You do not want to use the cloud because it’s not 100% private and 100 …
Is Expenses Book Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Expenses Book Plugin for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'expenses-book' plugin version 1.1.3 exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) and a strong adherence to secure coding practices, with 91% of outputs properly escaped and a significant majority of SQL queries utilizing prepared statements. The absence of external HTTP requests and bundled libraries is also reassuring. However, the static analysis reveals potential areas of concern. The presence of the 'system' dangerous function warrants investigation, as its misuse can lead to arbitrary code execution. Furthermore, three flows with unsanitized paths and one high-severity taint flow indicate potential vulnerabilities that could be exploited if not properly handled. While the current version shows no unpatched vulnerabilities, the identified code signals suggest a need for continued vigilance and thorough security testing.
Key Concerns
- Presence of dangerous function 'system'
- Flows with unsanitized paths identified
- High severity taint flow identified
Expenses Book Plugin for WordPress Security Vulnerabilities
Expenses Book Plugin for WordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Expenses Book Plugin for WordPress Attack Surface
AJAX Handlers 27
WordPress Hooks 11
Scheduled Events 1
Maintenance & Trust
Expenses Book Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Expenses Book Plugin for WordPress Alternatives
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
underConstruction
underconstruction
Creates a 'Coming Soon' page that will show for all users who are not logged in
Force Login
wp-force-login
Force Login is a simple lightweight plugin that requires visitors to log in to interact with the website.
HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce
hurrytimer
Create unlimited urgency and scarcity countdown timers for WordPress and WooCommerce to boost conversions and sales instantly.
My Private Site
jonradio-private-site
Make your WordPress site private with one click for family, projects, or teams. Protection for content, login, and registration.
Expenses Book Plugin for WordPress Developer Profile
4 plugins · 10 total installs
How We Detect Expenses Book Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/expenses-book/css/style.css/wp-content/plugins/expenses-book/js/script.js/wp-content/plugins/expenses-book/js/script.jsexpenses-book/style.css?ver=expenses-book/script.js?ver=HTML / DOM Fingerprints
wp_expenseszyx987_admin_page<!-- Expenses Book Plugin --><!-- Expenses Book Plugin Admin Page -->data-expenses-book-idwp_expenseszyx987_vars[expenses-book-dashboard][expenses-book-report]