Leo Footer Echo Security & Risk Analysis

wordpress.org/plugins/leo-footer-echo

A minimal, beginner-friendly plugin to echo customizable leo footer messages. Supports multiple messages, links, colors, and fonts.

0 active installs v2.1.0 PHP 8.0+ WP 5.0+ Updated Feb 23, 2026
customizationfontsfootermessagemulti-message
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Leo Footer Echo Safe to Use in 2026?

Generally Safe

Score 100/100

Leo Footer Echo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "leo-footer-echo" plugin v2.1.0 exhibits a generally good security posture based on the provided static analysis. The plugin has a very small attack surface, with only one shortcode and no unprotected entry points identified. The code demonstrates strong adherence to secure coding practices, with all SQL queries utilizing prepared statements and a high percentage of outputs being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. Additionally, the plugin has no recorded vulnerabilities, including CVEs, which indicates a history of secure development or diligent patching by the authors.

Despite these strengths, there are a few areas for attention. The complete absence of nonce checks is a notable omission, especially considering the presence of a shortcode which can potentially be exploited if user input is involved. While taint analysis found no issues, the lack of nonce protection means that any user-supplied data processed by the shortcode could theoretically be manipulated without proper verification. The single capability check is also a point to monitor, ensuring it's robust enough to prevent privilege escalation or unauthorized access if the shortcode performs sensitive actions.

In conclusion, "leo-footer-echo" v2.1.0 is a relatively secure plugin with a strong foundation in secure coding principles and a clean vulnerability history. The primary concern lies in the missing nonce checks for its shortcode functionality, which is a common vulnerability vector. However, given the overall lack of identified issues and the minimal attack surface, the risk appears manageable, provided the shortcode's functionality is not inherently sensitive or does not process user-supplied data without further sanitization within its logic.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Leo Footer Echo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Leo Footer Echo Release Timeline

v2.1.0Current
v2.0.2
Code Analysis
Analyzed Mar 17, 2026

Leo Footer Echo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
102 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

84% escaped121 total outputs
Attack Surface

Leo Footer Echo Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[leo_footer] leo-footer-echo.php:46
WordPress Hooks 5
actionadmin_menuleo-footer-echo.php:41
actionadmin_initleo-footer-echo.php:42
actionwp_enqueue_scriptsleo-footer-echo.php:43
actionadmin_enqueue_scriptsleo-footer-echo.php:44
actionwp_footerleo-footer-echo.php:45
Maintenance & Trust

Leo Footer Echo Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version8.0
Downloads221

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Leo Footer Echo Developer Profile

Sanjay L

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Leo Footer Echo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/leo-footer-echo/assets/css/leo-footer-echo.css/wp-content/plugins/leo-footer-echo/assets/js/admin.js
Script Paths
/wp-content/plugins/leo-footer-echo/assets/js/admin.js
Version Parameters
leo-footer-echo-style?ver=leo-footer-echo-admin-style?ver=leo-footer-echo-admin-js?ver=

HTML / DOM Fingerprints

JS Globals
leoFooterEcho
Shortcode Output
<div class="leo-footer-echo"
FAQ

Frequently Asked Questions about Leo Footer Echo