
OxyLeaf – Working and Relaxing App (SaaS ready) Security & Risk Analysis
wordpress.org/plugins/oxyleaf-app-working-and-relaxing-appOxyLeaf helps users improve focus and boost productivity with customizable ambient soundscapes and beautiful backgrounds.
Is OxyLeaf – Working and Relaxing App (SaaS ready) Safe to Use in 2026?
Generally Safe
Score 100/100OxyLeaf – Working and Relaxing App (SaaS ready) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'oxyleaf-app-working-and-relaxing-app' v1.0.2 demonstrates a strong security posture in several key areas. The static analysis reveals no critical or high-severity vulnerabilities through taint analysis, indicating that data flow within the plugin is generally well-sanitized. Furthermore, all detected SQL queries utilize prepared statements, and all output is properly escaped, significantly reducing the risk of SQL injection and cross-site scripting (XSS) vulnerabilities. The presence of nonce and capability checks on the majority of code signals suggests a deliberate effort to implement access controls, although the complete absence of AJAX handlers, REST API routes, shortcodes, and cron events limits the direct attack surface. The plugin also exhibits good practices by avoiding file operations and dangerous functions. The lack of any recorded CVEs in its vulnerability history further reinforces a perception of a well-maintained and secure plugin.
However, a few areas warrant attention. The plugin makes three external HTTP requests, which, if not handled securely, could potentially lead to vulnerabilities such as SSRF or information disclosure. While the analysis indicates no unsanitized paths in the limited taint flows, the limited scope of these flows (only 3 analyzed) means that the true extent of potential issues might not be fully captured. Additionally, the plugin bundles Select2 and Freemius v1.0. The security of these bundled libraries is critical; if they are outdated or have known vulnerabilities, they could introduce risks to the plugin. The overall security is good, but the limited attack surface and the reliance on bundled libraries for specific functionalities mean that any future changes or discoveries regarding these components could impact the plugin's security.
Key Concerns
- External HTTP requests made
- Bundled library Select2 may be outdated
- Bundled library Freemius v1.0 may be outdated
OxyLeaf – Working and Relaxing App (SaaS ready) Security Vulnerabilities
OxyLeaf – Working and Relaxing App (SaaS ready) Release Timeline
OxyLeaf – Working and Relaxing App (SaaS ready) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
OxyLeaf – Working and Relaxing App (SaaS ready) Attack Surface
WordPress Hooks 15
Maintenance & Trust
OxyLeaf – Working and Relaxing App (SaaS ready) Maintenance & Trust
Maintenance Signals
Community Trust
OxyLeaf – Working and Relaxing App (SaaS ready) Alternatives
Drafty In Here
drafty-in-here
Get email notifications of draft posts sitting in your WordPress Blog waiting to be published.
SAASPASS Two Factor Authentication – 2FA
saaspass-two-factor-authentication-2fa
SAASPASS provides the easiest way to secure your Wordpress with two-factor authentication (2FA) and enable passwordless security. MFA made amazing!
NINJA Workspace
ninja-workspace
Revolutionary workspace to keep your clients on your site and keep your brand in front of your customers.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
OxyLeaf – Working and Relaxing App (SaaS ready) Developer Profile
3 plugins · 0 total installs
How We Detect OxyLeaf – Working and Relaxing App (SaaS ready)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/admin/settings/dist/settings.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/admin/settings/dist/settings.css/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/select2/select2.full.min.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/select2/select2.min.css/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/toastr/toastr.min.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/toastr/toastr.min.css/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/bootstrap/bootstrap.min.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/bootstrap/bootstrap.min.css/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/admin/settings/dist/settings.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/select2/select2.full.min.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/toastr/toastr.min.js/wp-content/plugins/oxyleaf-app-working-and-relaxing-app/assets/vendor/bootstrap/bootstrap.min.jsoxyleaf-app-working-and-relaxing-app/assets/admin/settings/dist/settings.js?ver=v1oxyleaf-app-working-and-relaxing-app/assets/admin/settings/dist/settings.css?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/select2/select2.full.min.js?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/select2/select2.min.css?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/toastr/toastr.min.js?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/toastr/toastr.min.css?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/bootstrap/bootstrap.min.js?ver=v1oxyleaf-app-working-and-relaxing-app/assets/vendor/bootstrap/bootstrap.min.css?ver=v1HTML / DOM Fingerprints
OXYLEAF_ADMIN_SETTINGSOXYLEAF_APP_AJAX