Locco Emoticons Security & Risk Analysis

wordpress.org/plugins/locco-emoticons

Locco Emoticons is an emoticon set inspired by Andrei Sebastian.

10 active installs v1.4 PHP + WP 4.0+ Updated Nov 2, 2016
commentemoticonloccopostsmiley
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Locco Emoticons Safe to Use in 2026?

Generally Safe

Score 85/100

Locco Emoticons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The plugin "locco-emoticons" v1.4 exhibits a mixed security posture. On the positive side, the static analysis reveals no apparent dangerous functions, no raw SQL queries, and no file operations or external HTTP requests, which are all good indicators of secure coding practices. The absence of any known historical vulnerabilities (CVEs) also suggests a generally stable and well-maintained codebase over time. However, a significant concern arises from the complete lack of output escaping. With 10 total outputs and 0% properly escaped, this creates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the user interface. Furthermore, the absence of nonce checks and capability checks, especially if any of the entry points were to be discovered or introduced in future versions, means that the plugin lacks fundamental security controls to prevent unauthorized actions or access. While the current attack surface appears limited and protected, the critical flaw in output escaping and the lack of authorization checks represent substantial weaknesses that could be exploited if an entry point were to become accessible or if the plugin were to evolve in its functionality. The plugin's current strengths lie in its avoidance of common dangerous practices, but its weaknesses in output sanitation and authorization are critical and require immediate attention.

Key Concerns

  • 0% output properly escaped
  • 0 nonce checks
  • 0 capability checks
Vulnerabilities
None known

Locco Emoticons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Locco Emoticons Release Timeline

v1.4Current
v1.3
v1.2
v1.1
Code Analysis
Analyzed Apr 16, 2026

Locco Emoticons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped10 total outputs
Attack Surface

Locco Emoticons Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterthe_contentemoticons.php:28
filtercomment_textemoticons.php:29
actioncomment_formemoticons.php:30
actionwp_heademoticons.php:31
actionadmin_menuemoticons.php:32
filterplugin_action_linksemoticons.php:33
Maintenance & Trust

Locco Emoticons Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedNov 2, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

Locco Emoticons Developer Profile

Sebas

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Locco Emoticons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/locco-emoticons/checkbox0.gif/wp-content/plugins/locco-emoticons/checkbox1.gif

HTML / DOM Fingerprints

CSS Classes
codelistcode-rowcode-row-checkedcode-row-hovercode-check0code-check1
Data Attributes
name="Locco_Ro_emoticons_stat[name="Locco_Ro_emoticons_backlink"name="Locco_Ro_emoticons_action"name="Locco_Ro_emoticons_submit"id="Locco_Ro_emoticons_action"
FAQ

Frequently Asked Questions about Locco Emoticons