Inazo's flamingo automatically delete old messages Security & Risk Analysis

wordpress.org/plugins/inazo-flamingo-automatically-delete-old-messages

This plugin help you to auto removed all information stored by flamingo.

4K active installs v1.2 PHP + WP 4.6.0+ Updated Jul 26, 2024
contactcontact-form-7flamingogdprrgpd
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Inazo's flamingo automatically delete old messages Safe to Use in 2026?

Generally Safe

Score 92/100

Inazo's flamingo automatically delete old messages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'inazo-flamingo-automatically-delete-old-messages' v1.2 exhibits a generally positive security posture, with no reported vulnerabilities or critical code signals. The use of prepared statements for all SQL queries is a strong indicator of secure database interaction. The presence of a nonce check, although only one, suggests an awareness of potential cross-site request forgery (CSRF) risks. Furthermore, the absence of external HTTP requests and file operations limits the plugin's exposure to external attack vectors.

However, a significant concern arises from the complete lack of output escaping. This indicates that any data processed or displayed by the plugin could be vulnerable to cross-site scripting (XSS) attacks. While taint analysis did not reveal any unsanitized paths, the 0% proper output escaping is a glaring weakness. The plugin also lacks capability checks, which, combined with other entry points like cron events, could potentially be exploited if malicious data is introduced.

Given the clean vulnerability history, the plugin has historically been secure. However, the static analysis reveals a specific and serious flaw in output handling that needs immediate attention. The plugin's strengths lie in its database practices and limited external interactions, but the output escaping deficiency presents a tangible risk that must be addressed.

Key Concerns

  • Output is not properly escaped (0% escaped)
  • No capability checks found
Vulnerabilities
None known

Inazo's flamingo automatically delete old messages Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Inazo's flamingo automatically delete old messages Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
12 prepared
Unescaped Output
13
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared12 total queries

Output Escaping

0% escaped13 total outputs
Attack Surface

Inazo's flamingo automatically delete old messages Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuinazo-flamingo-automatically-delete-old-messages.php:31
actioninazo_flamingo_auto_trash_cron_task_dailyinazo-flamingo-automatically-delete-old-messages.php:32

Scheduled Events 1

inazo_flamingo_auto_trash_cron_task_daily
Maintenance & Trust

Inazo's flamingo automatically delete old messages Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 26, 2024
PHP min version
Downloads17K

Community Trust

Rating96/100
Number of ratings4
Active installs4K
Developer Profile

Inazo's flamingo automatically delete old messages Developer Profile

inazo

3 plugins · 4K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
2695 days
View full developer profile
Detection Fingerprints

How We Detect Inazo's flamingo automatically delete old messages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- on est sur la sauvegarde de la publicité --><!-- Suppression des contacts --><!-- Suppression des inbound --><!-- Suppression des outbound -->+2 more
FAQ

Frequently Asked Questions about Inazo's flamingo automatically delete old messages