
出勤・勤怠プラグイン Security & Risk Analysis
wordpress.org/plugins/os-attendance-management出勤・退勤などの勤怠(勤務状況)が管理できるプラグインです。
Is 出勤・勤怠プラグイン Safe to Use in 2026?
Generally Safe
Score 85/100出勤・勤怠プラグイン has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "os-attendance-management" plugin v1.3.21 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and has no known past vulnerabilities. The absence of external HTTP requests and file operations further contributes to a generally stable foundation. However, significant concerns arise from the static analysis results. The presence of the `unserialize` function, even if not immediately flagged as a critical taint flow, is a known vector for remote code execution if user-supplied data is involved. Furthermore, a high severity taint flow with unsanitized paths indicates a potential for vulnerabilities that require immediate attention. The low percentage of properly escaped output (19%) suggests a risk of cross-site scripting (XSS) vulnerabilities, especially if user-generated content is displayed without sufficient sanitization.
While the plugin's attack surface appears limited and all identified entry points have checks, the internal code quality presents risks. The critical flaw lies in the combination of the `unserialize` function and the identified high-severity unsanitized taint flow. The lack of historical vulnerabilities is a positive indicator of past development diligence, but it does not negate the risks present in the current version's code. A balanced conclusion is that the plugin has strengths in its adherence to secure database practices and a clean vulnerability history, but the presence of dangerous functions and unsanitized data flows, coupled with poor output escaping, creates a notable risk profile that needs to be addressed.
Key Concerns
- High severity taint flow with unsanitized paths
- Low output escaping percentage (19%)
- Dangerous function detected (unserialize)
出勤・勤怠プラグイン Security Vulnerabilities
出勤・勤怠プラグイン Release Timeline
出勤・勤怠プラグイン Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
出勤・勤怠プラグイン Attack Surface
Shortcodes 2
WordPress Hooks 14
Maintenance & Trust
出勤・勤怠プラグイン Maintenance & Trust
Maintenance Signals
Community Trust
出勤・勤怠プラグイン Alternatives
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
Admin Menu Editor
admin-menu-editor
Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.
Adminimize
adminimize
Adminimize that lets you hide 'unnecessary' items from the WordPress backend
出勤・勤怠プラグイン Developer Profile
4 plugins · 630 total installs
How We Detect 出勤・勤怠プラグイン
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/os-attendance-management/css/admin-style.css/wp-content/plugins/os-attendance-management/css/user-style.css/wp-content/plugins/os-attendance-management/css/style.css/wp-content/plugins/os-attendance-management/js/common.js/wp-content/plugins/os-attendance-management/js/admin.js/wp-content/plugins/os-attendance-management/js/user.js/wp-content/plugins/os-attendance-management/js/common.js/wp-content/plugins/os-attendance-management/js/admin.js/wp-content/plugins/os-attendance-management/js/user.jsos-attendance-management/css/admin-style.css?ver=os-attendance-management/css/user-style.css?ver=os-attendance-management/css/style.css?ver=os-attendance-management/js/common.js?ver=os-attendance-management/js/admin.js?ver=os-attendance-management/js/user.js?ver=HTML / DOM Fingerprints
osam-admin-wraposam-option-wraposam-list-wraposam-post-wraposam-help-wraposam-write-wraposam-format-wraposam-agreement-wrapdata-osam-user-iddata-osam-working-idosam_common_dataattendanceAdminattendanceUserattendanceProf