OxyLeaf – Working and Relaxing App (SaaS ready) Security & Risk Analysis

wordpress.org/plugins/oxyleaf-app-working-and-relaxing-app

OxyLeaf helps users improve focus and boost productivity with customizable ambient soundscapes and beautiful backgrounds.

0 active installs v1.0.2 PHP 8.2+ WP 6.4+ Updated Jan 4, 2026
focusproductivityrelaxationsaasspa
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OxyLeaf – Working and Relaxing App (SaaS ready) Safe to Use in 2026?

Generally Safe

Score 100/100

OxyLeaf – Working and Relaxing App (SaaS ready) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin 'oxyleaf-app-working-and-relaxing-app' v1.0.2 demonstrates a strong security posture in several key areas. The static analysis reveals no critical or high-severity vulnerabilities through taint analysis, indicating that data flow within the plugin is generally well-sanitized. Furthermore, all detected SQL queries utilize prepared statements, and all output is properly escaped, significantly reducing the risk of SQL injection and cross-site scripting (XSS) vulnerabilities. The presence of nonce and capability checks on the majority of code signals suggests a deliberate effort to implement access controls, although the complete absence of AJAX handlers, REST API routes, shortcodes, and cron events limits the direct attack surface. The plugin also exhibits good practices by avoiding file operations and dangerous functions. The lack of any recorded CVEs in its vulnerability history further reinforces a perception of a well-maintained and secure plugin.

However, a few areas warrant attention. The plugin makes three external HTTP requests, which, if not handled securely, could potentially lead to vulnerabilities such as SSRF or information disclosure. While the analysis indicates no unsanitized paths in the limited taint flows, the limited scope of these flows (only 3 analyzed) means that the true extent of potential issues might not be fully captured. Additionally, the plugin bundles Select2 and Freemius v1.0. The security of these bundled libraries is critical; if they are outdated or have known vulnerabilities, they could introduce risks to the plugin. The overall security is good, but the limited attack surface and the reliance on bundled libraries for specific functionalities mean that any future changes or discoveries regarding these components could impact the plugin's security.

Key Concerns

  • External HTTP requests made
  • Bundled library Select2 may be outdated
  • Bundled library Freemius v1.0 may be outdated
Vulnerabilities
None known

OxyLeaf – Working and Relaxing App (SaaS ready) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

OxyLeaf – Working and Relaxing App (SaaS ready) Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

OxyLeaf – Working and Relaxing App (SaaS ready) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
0
1092 escaped
Nonce Checks
7
Capability Checks
9
File Operations
0
External Requests
3
Bundled Libraries
2

Bundled Libraries

Select2Freemius1.0

SQL Query Safety

100% prepared10 total queries

Output Escaping

100% escaped1092 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
updateUserField (app/Controllers/UserCtrl.php:311)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

OxyLeaf – Working and Relaxing App (SaaS ready) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionadmin_menuapp/Hooks/ActionAdminMenu.php:13
actionadmin_noticesapp/Hooks/ActionAdminNotice.php:10
actionadmin_enqueue_scriptsapp/Hooks/ActionEnqueueScripts.php:16
actionadd_meta_boxesapp/Hooks/ActionMetaBoxes.php:15
actioninitapp/Hooks/ActionRegisterCpt.php:11
actionrest_api_initapp/Hooks/ActionRestApi.php:17
actionrest_api_initapp/Hooks/ActionRestApi.php:18
actionsave_postapp/Hooks/ActionSavePost.php:14
actionsave_postapp/Hooks/ActionSavePost.php:15
actionadmin_initapp/Hooks/ActionSettings.php:11
actioninitapp/Hooks/ActionTaxonomie.php:17
actioninitapp/Hooks/ActionTaxonomie.php:18
filtertemplate_includeapp/Hooks/FilterTemplateInclude.php:11
filteroxygen_app_filter_frontend_template_requestapp/Hooks/FiltersCustom.php:8
actionowarasr_fs_loadedoxyleaf-app-working-and-relaxing-app.php:21
Maintenance & Trust

OxyLeaf – Working and Relaxing App (SaaS ready) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 4, 2026
PHP min version8.2
Downloads182

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

OxyLeaf – Working and Relaxing App (SaaS ready) Developer Profile

sakurapixel

3 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OxyLeaf – Working and Relaxing App (SaaS ready)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/admin/settings/dist/settings.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/admin/settings/dist/settings.css/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/select2/select2.full.min.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/select2/select2.min.css/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/toastr/toastr.min.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/toastr/toastr.min.css/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/bootstrap/bootstrap.min.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/bootstrap/bootstrap.min.css
Script Paths
/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/admin/settings/dist/settings.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/select2/select2.full.min.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/toastr/toastr.min.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/bootstrap/bootstrap.min.js
Version Parameters
oxyleaf-app-working-and-relaxing-app/assets/admin/settings/dist/settings.js?ver=v1oxyleaf-app-working-and-relaxing-app/assets/admin/settings/dist/settings.css?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/select2/select2.full.min.js?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/select2/select2.min.css?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/toastr/toastr.min.js?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/toastr/toastr.min.css?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/bootstrap/bootstrap.min.js?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/bootstrap/bootstrap.min.css?ver=v1

HTML / DOM Fingerprints

JS Globals
OXYLEAF_ADMIN_SETTINGSOXYLEAF_APP_AJAX
FAQ

Frequently Asked Questions about OxyLeaf – Working and Relaxing App (SaaS ready)