
Eyoung Service Online System – Eyoung在线客服系统 Security & Risk Analysis
wordpress.org/plugins/eyoungEyoung Service Online System (Eyoung在线客服系统), 为WordPress网站提供网页版的在线即时沟通工具,是一对一沟通服务的客服插件.
Is Eyoung Service Online System – Eyoung在线客服系统 Safe to Use in 2026?
Generally Safe
Score 100/100Eyoung Service Online System – Eyoung在线客服系统 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "eyoung" v1.0 plugin exhibits a concerning security posture primarily due to a large, unprotected attack surface. While the plugin demonstrates good practices in SQL query preparation and output escaping, the absence of authentication checks on all 31 AJAX handlers is a significant vulnerability. This means any user, regardless of their role or logged-in status, can potentially trigger these functions, opening the door to various attacks if the AJAX handlers themselves have exploitable logic. The taint analysis, although limited, shows flows with unsanitized paths, which could be a precursor to more severe issues if they interact with user-controlled input. The plugin's clean vulnerability history is positive, suggesting it hasn't been a target or has been developed with a degree of care, but this does not mitigate the inherent risks identified in the static analysis. The lack of any nonce or capability checks on the entry points is a critical oversight that overshadows otherwise decent coding practices.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint flows
- No nonce checks on entry points
- No capability checks on entry points
Eyoung Service Online System – Eyoung在线客服系统 Security Vulnerabilities
Eyoung Service Online System – Eyoung在线客服系统 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Eyoung Service Online System – Eyoung在线客服系统 Attack Surface
AJAX Handlers 31
WordPress Hooks 9
Maintenance & Trust
Eyoung Service Online System – Eyoung在线客服系统 Maintenance & Trust
Maintenance Signals
Community Trust
Eyoung Service Online System – Eyoung在线客服系统 Alternatives
Eyoung Service Online System – Eyoung在线客服系统 Developer Profile
2 plugins · 20 total installs
How We Detect Eyoung Service Online System – Eyoung在线客服系统
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eyoung/dist/css/chunk-vendors.css/wp-content/plugins/eyoung/dist/css/chunk-common.css/wp-content/plugins/eyoung/dist/css/app.css/wp-content/plugins/eyoung/dist/js/chunk-vendors.js/wp-content/plugins/eyoung/dist/js/chunk-common.js/wp-content/plugins/eyoung/dist/js/app.js/wp-content/plugins/eyoung/dist/js/chunk-vendors.js/wp-content/plugins/eyoung/dist/js/chunk-common.js/wp-content/plugins/eyoung/dist/js/app.jseyoung/dist/css/chunk-vendors.css?ver=eyoung/dist/css/chunk-common.css?ver=eyoung/dist/css/app.css?ver=eyoung/dist/js/chunk-vendors.js?ver=eyoung/dist/js/chunk-common.js?ver=eyoung/dist/js/app.js?ver=HTML / DOM Fingerprints
eyoung_chatboxeyoung_chatbox_iconeyoung_chatbox_wrapeyoung_chatbox_message<!-- Eyoung Service Online Chat Box -->data-eyoung-iddata-eyoung-user-ideyoung_config/wp-json/eyoung/v1/chat[eyoung_chat]