OneButton – Log Security & Risk Analysis

wordpress.org/plugins/onebutton-log

Monitor and analyze search engine bot and AI bot visits to your WordPress site and optimize your SEO performance.

40 active installs v1.10.0 PHP + WP 5.0+ Updated Jul 21, 2025
analyticsbotgooglebotlogseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is OneButton – Log Safe to Use in 2026?

Generally Safe

Score 100/100

OneButton – Log has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "onebutton-log" v1.10.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries are prepared), and a very high percentage of properly escaped output are commendable. The plugin also correctly implements nonce and capability checks on its entry points, and there are no identified critical or high severity taint flows. The lack of any historical vulnerabilities further bolsters confidence in its current security.

However, there are a couple of areas that warrant attention. While the attack surface is small and all entry points appear to have authentication checks, the presence of file operations (6 instances) could potentially be a concern if not handled with extreme care. Without further details on how these file operations are implemented, it's difficult to definitively rule out risks. Similarly, while no external HTTP requests are made, this can be a common vector for vulnerabilities in other plugins. The absence of bundled libraries is a positive indicator, as outdated libraries can introduce significant security risks.

In conclusion, "onebutton-log" v1.10.0 appears to be a well-secured plugin. Its diligent use of prepared statements, output escaping, and security checks on its limited attack surface are significant strengths. The primary areas to monitor would be the implementation of its file operations to ensure they cannot be exploited. The complete lack of historical vulnerabilities and zero reported CVEs is a strong indicator of ongoing security diligence.

Key Concerns

  • File operations present (potential risk)
Vulnerabilities
None known

OneButton – Log Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

OneButton – Log Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
163 escaped
Nonce Checks
8
Capability Checks
6
File Operations
6
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped172 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
onebutton_settings_page (onebutton-log.php:626)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

OneButton – Log Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_onebutton_get_calendar_dataonebutton-log.php:1471
authwp_ajax_onebutton_get_calendar_datatrunk\onebutton-log.php:928
WordPress Hooks 14
actionwponebutton-log.php:145
actionadmin_menuonebutton-log.php:183
actionadmin_menuonebutton-log.php:620
actiononebutton_auto_cleanuponebutton-log.php:767
actionadmin_initonebutton-log.php:798
actionwp_dashboard_setuponebutton-log.php:1043
actionupgrader_process_completeonebutton-log.php:1617
actionwptrunk\onebutton-log.php:145
actionadmin_menutrunk\onebutton-log.php:183
actionadmin_menutrunk\onebutton-log.php:198
actionadmin_inittrunk\onebutton-log.php:257
actionwp_dashboard_setuptrunk\onebutton-log.php:502
actionadmin_menutrunk\onebutton-log.php:972
actionupgrader_process_completetrunk\onebutton-log.php:1075

Scheduled Events 1

onebutton_auto_cleanup
Maintenance & Trust

OneButton – Log Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 21, 2025
PHP min version
Downloads901

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

OneButton – Log Developer Profile

Ekin Yalıncak

2 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OneButton – Log

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about OneButton – Log