Eyoung Service Online System – Eyoung在线客服系统 Security & Risk Analysis

wordpress.org/plugins/eyoung

Eyoung Service Online System (Eyoung在线客服系统), 为WordPress网站提供网页版的在线即时沟通工具,是一对一沟通服务的客服插件.

10 active installs v1.0 PHP + WP 4.8+ Updated Unknown
%e8%81%8a%e5%a4%a9webim%e5%9c%a8%e7%ba%bf%e5%ae%a2%e6%9c%8d%e6%b2%9f%e9%80%9a%e4%ba%92%e5%8a%a8
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Eyoung Service Online System – Eyoung在线客服系统 Safe to Use in 2026?

Generally Safe

Score 100/100

Eyoung Service Online System – Eyoung在线客服系统 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "eyoung" v1.0 plugin exhibits a concerning security posture primarily due to a large, unprotected attack surface. While the plugin demonstrates good practices in SQL query preparation and output escaping, the absence of authentication checks on all 31 AJAX handlers is a significant vulnerability. This means any user, regardless of their role or logged-in status, can potentially trigger these functions, opening the door to various attacks if the AJAX handlers themselves have exploitable logic. The taint analysis, although limited, shows flows with unsanitized paths, which could be a precursor to more severe issues if they interact with user-controlled input. The plugin's clean vulnerability history is positive, suggesting it hasn't been a target or has been developed with a degree of care, but this does not mitigate the inherent risks identified in the static analysis. The lack of any nonce or capability checks on the entry points is a critical oversight that overshadows otherwise decent coding practices.

Key Concerns

  • Unprotected AJAX handlers
  • Unsanitized paths in taint flows
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Eyoung Service Online System – Eyoung在线客服系统 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Eyoung Service Online System – Eyoung在线客服系统 Code Analysis

Dangerous Functions
0
Raw SQL Queries
12
23 prepared
Unescaped Output
1
47 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

66% prepared35 total queries

Output Escaping

98% escaped48 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
getAddressByIp (classes\front.class.php:335)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
31 unprotected

Eyoung Service Online System – Eyoung在线客服系统 Attack Surface

Entry Points31
Unprotected31

AJAX Handlers 31

authwp_ajax_eys_settingclasses\admin.class.php:300
authwp_ajax_eys_severclasses\admin.class.php:301
authwp_ajax_eys_upsocketclasses\admin.class.php:302
authwp_ajax_eys_getCustomerclasses\admin.class.php:303
authwp_ajax_eys_setCustomerclasses\admin.class.php:304
authwp_ajax_eys_delCustomerclasses\admin.class.php:305
authwp_ajax_eys_getChatAllclasses\admin.class.php:306
authwp_ajax_eys_delChatAllclasses\admin.class.php:307
authwp_ajax_eys_imageuploadclasses\admin.class.php:312
authwp_ajax_eys_setContentclasses\front.class.php:536
authwp_ajax_eys_getChatclasses\front.class.php:537
authwp_ajax_eys_getOfflineMsgclasses\front.class.php:538
authwp_ajax_eys_setChatViewclasses\front.class.php:539
authwp_ajax_eys_setTrackclasses\front.class.php:540
authwp_ajax_eys_getTrackclasses\front.class.php:541
authwp_ajax_eys_setUserFieldclasses\front.class.php:542
authwp_ajax_eys_setOfflineReplyclasses\front.class.php:543
authwp_ajax_eys_getOfflineReplyclasses\front.class.php:544
authwp_ajax_eys_getAddressByIpclasses\front.class.php:545
authwp_ajax_eys_sendtomailclasses\front.class.php:546
authwp_ajax_eys_uploadImageclasses\front.class.php:547
authwp_ajax_eys_uploadFileclasses\front.class.php:548
noprivwp_ajax_eys_setContentclasses\front.class.php:549
noprivwp_ajax_eys_getChatclasses\front.class.php:550
noprivwp_ajax_eys_getOfflineMsgclasses\front.class.php:551
noprivwp_ajax_eys_setChatViewclasses\front.class.php:552
noprivwp_ajax_eys_setTrackclasses\front.class.php:553
noprivwp_ajax_eys_setUserFieldclasses\front.class.php:554
noprivwp_ajax_eys_sendtomailclasses\front.class.php:555
noprivwp_ajax_eys_uploadImageclasses\front.class.php:556
noprivwp_ajax_eys_uploadFileclasses\front.class.php:557
WordPress Hooks 9
actionadmin_menuclasses\admin.class.php:299
filterplugin_action_linksclasses\admin.class.php:308
actionadmin_enqueue_scriptsclasses\admin.class.php:309
actionplugins_loadedclasses\front.class.php:529
filterwp_handle_upload_prefilterclasses\front.class.php:559
filtertemplate_includeclasses\front.class.php:567
filterthe_contentclasses\front.class.php:569
actionwp_footerclasses\front.class.php:570
actionwp_enqueue_scriptsclasses\front.class.php:572
Maintenance & Trust

Eyoung Service Online System – Eyoung在线客服系统 Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedUnknown
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Eyoung Service Online System – Eyoung在线客服系统 Developer Profile

yuyaoit

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Eyoung Service Online System – Eyoung在线客服系统

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eyoung/dist/css/chunk-vendors.css/wp-content/plugins/eyoung/dist/css/chunk-common.css/wp-content/plugins/eyoung/dist/css/app.css/wp-content/plugins/eyoung/dist/js/chunk-vendors.js/wp-content/plugins/eyoung/dist/js/chunk-common.js/wp-content/plugins/eyoung/dist/js/app.js
Script Paths
/wp-content/plugins/eyoung/dist/js/chunk-vendors.js/wp-content/plugins/eyoung/dist/js/chunk-common.js/wp-content/plugins/eyoung/dist/js/app.js
Version Parameters
eyoung/dist/css/chunk-vendors.css?ver=eyoung/dist/css/chunk-common.css?ver=eyoung/dist/css/app.css?ver=eyoung/dist/js/chunk-vendors.js?ver=eyoung/dist/js/chunk-common.js?ver=eyoung/dist/js/app.js?ver=

HTML / DOM Fingerprints

CSS Classes
eyoung_chatboxeyoung_chatbox_iconeyoung_chatbox_wrapeyoung_chatbox_message
HTML Comments
<!-- Eyoung Service Online Chat Box -->
Data Attributes
data-eyoung-iddata-eyoung-user-id
JS Globals
eyoung_config
REST Endpoints
/wp-json/eyoung/v1/chat
Shortcode Output
[eyoung_chat]
FAQ

Frequently Asked Questions about Eyoung Service Online System – Eyoung在线客服系统