
Mcc Automated Security & Risk Analysis
wordpress.org/plugins/mobile-cost-control-automatedGet accurate information from your prospect's bills and show them a better offer instantly. Show your prospects their line count, total bill, dat …
Is Mcc Automated Safe to Use in 2026?
Generally Safe
Score 85/100Mcc Automated has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mobile-cost-control-automated plugin v1.2.8 exhibits a generally strong security posture, with several good practices in place. The majority of SQL queries utilize prepared statements, and all output is properly escaped, significantly reducing the risk of common web vulnerabilities like SQL injection and cross-site scripting. The absence of known CVEs and past vulnerabilities further suggests a well-maintained codebase. However, the static analysis reveals critical concerns. Specifically, there are two taint flows with unsanitized paths, indicating a potential for data to be mishandled or exploited if input is not properly validated before being used in sensitive operations. The lack of nonce checks and capability checks on entry points, even though the attack surface is small and no AJAX/REST API routes are unprotected, is a significant omission. While there are no direct authentication bypass vulnerabilities identified in the provided data, these missing checks can be exploited in conjunction with other weaknesses to escalate privileges or perform unauthorized actions. The bundled Select2 library also warrants attention, as outdated versions can introduce vulnerabilities, though no specific version information is provided to assess this risk directly.
Key Concerns
- Critical taint flows with unsanitized paths found
- No nonce checks implemented
- No capability checks implemented
- Bundled library (Select2) may be outdated
Mcc Automated Security Vulnerabilities
Mcc Automated Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Mcc Automated Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Mcc Automated Maintenance & Trust
Maintenance Signals
Community Trust
Mcc Automated Developer Profile
2 plugins · 0 total installs
How We Detect Mcc Automated
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mobile-cost-control-automated/css/mcc-automated-public.css/wp-content/plugins/mobile-cost-control-automated/css/dropzone.min.css/wp-content/plugins/mobile-cost-control-automated/js/mcc-automated-public.js/wp-content/plugins/mobile-cost-control-automated/js/dropzone.min.js/wp-content/plugins/mobile-cost-control-automated/js/mcc-automated-public.js/wp-content/plugins/mobile-cost-control-automated/js/dropzone.min.jsmobile-cost-control-automated/css/mcc-automated-public.css?ver=mobile-cost-control-automated/css/dropzone.min.css?ver=mobile-cost-control-automated/js/mcc-automated-public.js?ver=mobile-cost-control-automated/js/dropzone.min.js?ver=HTML / DOM Fingerprints
mccAutomatedObj[mcc_automated_form_1]