LineOne Security & Risk Analysis

wordpress.org/plugins/lineone-one

LineOne.one LineOne - your websites greatest agent. LineOne connects you to your customers straight away on the phone so you can talk and help your u …

0 active installs v1.0.0 PHP + WP 4.6+ Updated Unknown
lineone
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is LineOne Safe to Use in 2026?

Generally Safe

Score 100/100

LineOne has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'lineone-one' plugin v1.0.0 exhibits a generally good security posture based on the provided static analysis. The absence of any recorded vulnerabilities in its history and the lack of critical signals like dangerous functions or unhandled taint flows are positive indicators. The code also demonstrates good practices by using prepared statements for all SQL queries and including a nonce check.

However, there are areas for concern. The plugin has an "attack surface" of 0 entry points without protection, which is excellent. Nevertheless, only 50% of its output is properly escaped, indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs handle user-supplied data. Furthermore, the absence of capability checks on any entry points means that if any were to be introduced in future versions without proper authorization checks, they could be exploited by unauthenticated users. The lack of documented vulnerabilities might also be a reflection of the plugin's age or lack of widespread use, rather than a guarantee of perfect security.

In conclusion, while the plugin's current state and history suggest a low immediate risk, the unescaped output and the lack of capability checks represent potential weaknesses that should be addressed to further strengthen its security. The absence of a larger attack surface and the use of prepared statements are significant strengths. It's crucial to ensure that any future development maintains these standards and addresses the identified output escaping and authorization concerns.

Key Concerns

  • Output escaping is only 50% proper
  • No capability checks on entry points
Vulnerabilities
None known

LineOne Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LineOne Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
wplo_handle_form (lineone-widget.php:96)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LineOne Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menulineone-widget.php:24
actionwp_print_scriptslineone-widget.php:68
actionwp_print_scriptslineone-widget.php:78
actionplugins_loadedlineone-widget.php:91
actionwp_enqueue_scriptslineone-widget.php:119
filterscript_loader_taglineone-widget.php:130
Maintenance & Trust

LineOne Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedUnknown
PHP min version
Downloads628

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

LineOne Alternatives

No alternatives data available yet.

Developer Profile

LineOne Developer Profile

happyconnect

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LineOne

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lineone-one/widget-pop-up.js
Script Paths
https://lineone.one/widget-pop-up/widget-pop-up.js

HTML / DOM Fingerprints

CSS Classes
lineone_widget_settings
Data Attributes
data-widgetbaseurldata-widgetcustomeridid="lineone_widget_script"
FAQ

Frequently Asked Questions about LineOne