Ojama Flying Sankocho Security & Risk Analysis

wordpress.org/plugins/ojama-flying-sankocho

This plugin doesn't help with anything. This plugin shows desktop mascot that is the bird. The Japanese Paradise Flycatcher painted simply comes …

10 active installs v1.0 PHP + WP 4.5+ Updated Nov 9, 2017
amusementbirdfunmascotpastime
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ojama Flying Sankocho Safe to Use in 2026?

Generally Safe

Score 85/100

Ojama Flying Sankocho has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

Based on the static analysis, "ojama-flying-sankocho" v1.0 exhibits a surprisingly robust security posture. The complete absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and the exclusive use of prepared statements for SQL queries are all excellent security practices. This indicates a diligent approach to development concerning common web vulnerabilities.

However, the security analysis does highlight some areas of concern. A critical weakness lies in the low percentage of properly escaped output (29%). This suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, where user-supplied input could be rendered directly in the browser without proper sanitization. The lack of any nonce checks or capability checks on entry points, while the entry points themselves are reported as zero, still represents a potential gap if any entry points were to be introduced or discovered. The vulnerability history being clean is positive, but it might also be a reflection of the limited attack surface rather than inherent security, especially given the output escaping issue.

In conclusion, while the plugin benefits from a minimal attack surface and secure data handling for SQL, the poor output escaping is a significant vulnerability that needs immediate attention. The absence of known CVEs is a positive indicator, but the identified code signals suggest that this could change if the output escaping is not addressed. Developers should prioritize fixing the unescaped output to mitigate XSS risks and maintain a strong security profile.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Ojama Flying Sankocho Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ojama Flying Sankocho Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped28 total outputs
Attack Surface

Ojama Flying Sankocho Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwp_enqueue_scriptsflying_jpf.php:75
actionwp_footerflying_jpf.php:78
actionadmin_initflying_jpf.php:85
actionwp_enqueue_scriptsflying_jpf.php:300
actionwp_footerflying_jpf.php:301
actionadmin_menuflying_jpf.php:311
Maintenance & Trust

Ojama Flying Sankocho Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 9, 2017
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Ojama Flying Sankocho Developer Profile

strix-bubol5

3 plugins · 290 total installs

83
trust score
Avg Security Score
93/100
Avg Patch Time
31 days
View full developer profile
Detection Fingerprints

How We Detect Ojama Flying Sankocho

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ojama-flying-sankocho/js/ojama_flying_sankocho.js/wp-content/plugins/ojama-flying-sankocho/css/ojama_flying_sankocho.css
Script Paths
/wp-content/plugins/ojama-flying-sankocho/js/ojama_flying_sankocho.js
Version Parameters
ojama-flying-sankocho/js/ojama_flying_sankocho.js?ver=ojama-flying-sankocho/css/ojama_flying_sankocho.css?ver=

HTML / DOM Fingerprints

Data Attributes
name="flying_sankocho_option[onlypage]"name="flying_sankocho_option[directpage]"name="flying_sankocho_option[directcustom]"name="flying_sankocho_option[blanktime]"name="flying_sankocho_option[waittime]"
JS Globals
flying_sankocho_option
FAQ

Frequently Asked Questions about Ojama Flying Sankocho