Mcc Automated Security & Risk Analysis

wordpress.org/plugins/mobile-cost-control-automated

Get accurate information from your prospect's bills and show them a better offer instantly. Show your prospects their line count, total bill, dat …

0 active installs v1.2.8 PHP 7.0+ WP 5.0.13+ Updated Sep 19, 2022
b2b-sales-leadsmobile-bill-analyzerread-prospects-billsupload-offer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Mcc Automated Safe to Use in 2026?

Generally Safe

Score 85/100

Mcc Automated has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The mobile-cost-control-automated plugin v1.2.8 exhibits a generally strong security posture, with several good practices in place. The majority of SQL queries utilize prepared statements, and all output is properly escaped, significantly reducing the risk of common web vulnerabilities like SQL injection and cross-site scripting. The absence of known CVEs and past vulnerabilities further suggests a well-maintained codebase. However, the static analysis reveals critical concerns. Specifically, there are two taint flows with unsanitized paths, indicating a potential for data to be mishandled or exploited if input is not properly validated before being used in sensitive operations. The lack of nonce checks and capability checks on entry points, even though the attack surface is small and no AJAX/REST API routes are unprotected, is a significant omission. While there are no direct authentication bypass vulnerabilities identified in the provided data, these missing checks can be exploited in conjunction with other weaknesses to escalate privileges or perform unauthorized actions. The bundled Select2 library also warrants attention, as outdated versions can introduce vulnerabilities, though no specific version information is provided to assess this risk directly.

Key Concerns

  • Critical taint flows with unsanitized paths found
  • No nonce checks implemented
  • No capability checks implemented
  • Bundled library (Select2) may be outdated
Vulnerabilities
None known

Mcc Automated Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Mcc Automated Code Analysis

Dangerous Functions
0
Raw SQL Queries
15
318 prepared
Unescaped Output
0
127 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
6
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

95% prepared333 total queries

Output Escaping

100% escaped127 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
handle_form_1_step_2_submit (public\class-mcc-automated-public.php:2330)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Mcc Automated Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mcc_automated_form_1] public\class-mcc-automated-public.php:111
WordPress Hooks 11
actionadmin_initadmin\class-mcc-automated-admin.php:214
actionplugins_loadedincludes\class-mcc-automated.php:131
actionadmin_enqueue_scriptsincludes\class-mcc-automated.php:147
actionadmin_enqueue_scriptsincludes\class-mcc-automated.php:148
actionadmin_menuincludes\class-mcc-automated.php:150
actioninitincludes\class-mcc-automated.php:166
actionadmin_post_nopriv_mcc_automated_form_1_step_1public\class-mcc-automated-public.php:113
actionadmin_post_mcc_automated_form_1_step_1public\class-mcc-automated-public.php:115
actionadmin_post_nopriv_mcc_automated_form_1_step_2public\class-mcc-automated-public.php:117
actionadmin_post_mcc_automated_form_1_step_2public\class-mcc-automated-public.php:119
actionupgrader_process_completepublic\class-mcc-automated-public.php:121
Maintenance & Trust

Mcc Automated Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 19, 2022
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Mcc Automated Developer Profile

validas

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mcc Automated

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mobile-cost-control-automated/css/mcc-automated-public.css/wp-content/plugins/mobile-cost-control-automated/css/dropzone.min.css/wp-content/plugins/mobile-cost-control-automated/js/mcc-automated-public.js/wp-content/plugins/mobile-cost-control-automated/js/dropzone.min.js
Script Paths
/wp-content/plugins/mobile-cost-control-automated/js/mcc-automated-public.js/wp-content/plugins/mobile-cost-control-automated/js/dropzone.min.js
Version Parameters
mobile-cost-control-automated/css/mcc-automated-public.css?ver=mobile-cost-control-automated/css/dropzone.min.css?ver=mobile-cost-control-automated/js/mcc-automated-public.js?ver=mobile-cost-control-automated/js/dropzone.min.js?ver=

HTML / DOM Fingerprints

JS Globals
mccAutomatedObj
Shortcode Output
[mcc_automated_form_1]
FAQ

Frequently Asked Questions about Mcc Automated