Skittybop Security & Risk Analysis

wordpress.org/plugins/skittybop

Adds video calls to WordPress!

200 active installs v1.1.0 PHP 5.3+ WP 6.2+ Updated Feb 11, 2026
operatorsskittybopsupportvideo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Skittybop Safe to Use in 2026?

Generally Safe

Score 100/100

Skittybop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'skittybop' v1.1.0 demonstrates a generally good security posture based on the provided static analysis. A significant strength is the complete absence of unauthenticated AJAX handlers, which is a critical entry point for many attacks. Furthermore, all identified SQL queries utilize prepared statements, mitigating the risk of SQL injection. The presence of numerous capability checks also suggests an awareness of WordPress's role-based access control. However, a notable weakness lies in the output escaping, with 23% of outputs being improperly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. The vulnerability history being clean is a positive indicator, suggesting a lack of past exploitable issues, but this should be viewed alongside the potential for undiscovered vulnerabilities, especially given the unescaped outputs.

Key Concerns

  • Improper output escaping on 23% of outputs
Vulnerabilities
None known

Skittybop Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Skittybop Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
52 prepared
Unescaped Output
22
75 escaped
Nonce Checks
8
Capability Checks
15
File Operations
0
External Requests
4
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

100% prepared52 total queries

Output Escaping

77% escaped97 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
fetch_history (includes\skittybop-ajax.php:134)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Skittybop Attack Surface

Entry Points12
Unprotected0

AJAX Handlers 12

authwp_ajax_skittybop_fetch_operatorsincludes\skittybop-ajax.php:16
authwp_ajax_skittybop_callincludes\skittybop-ajax.php:17
noprivwp_ajax_skittybop_callincludes\skittybop-ajax.php:18
authwp_ajax_skittybop_fetch_callsincludes\skittybop-ajax.php:19
authwp_ajax_skittybop_delete_callsincludes\skittybop-ajax.php:20
authwp_ajax_skittybop_change_call_statusincludes\skittybop-ajax.php:21
noprivwp_ajax_skittybop_change_call_statusincludes\skittybop-ajax.php:22
authwp_ajax_skittybop_change_call_timestampincludes\skittybop-ajax.php:23
noprivwp_ajax_skittybop_change_call_timestampincludes\skittybop-ajax.php:24
authwp_ajax_skittybop_fetch_subscription_planincludes\skittybop-ajax.php:25
authwp_ajax_skittybop_send_messageincludes\skittybop-ajax.php:26
noprivwp_ajax_skittybop_send_messageincludes\skittybop-ajax.php:27
WordPress Hooks 21
filterheartbeat_receivedincludes\skittybop-ajax.php:29
filterheartbeat_nopriv_receivedincludes\skittybop-ajax.php:30
filterheartbeat_settingsskittybop.php:81
actionadmin_initskittybop.php:84
actioninitskittybop.php:85
actioninitskittybop.php:86
actionset_logged_in_cookieskittybop.php:117
actionwp_logoutskittybop.php:118
actionadmin_menuskittybop.php:122
actionadmin_enqueue_scriptsskittybop.php:123
actionadmin_enqueue_scriptsskittybop.php:124
filteradmin_footer_textskittybop.php:125
filterset-screen-optionskittybop.php:127
filterset-screen-optionskittybop.php:128
actionadmin_noticesskittybop.php:130
actiontemplate_redirectskittybop.php:133
filterpage_templateskittybop.php:134
actionwp_enqueue_scriptsskittybop.php:136
actionwp_enqueue_scriptsskittybop.php:137
actionwp_footerskittybop.php:138
actionwp_footerskittybop.php:139
Maintenance & Trust

Skittybop Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 11, 2026
PHP min version5.3
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Skittybop Developer Profile

Remwes, LLC

2 plugins · 400 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Skittybop

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/skittybop/assets/css/skittybop-admin.css/wp-content/plugins/skittybop/assets/css/skittybop.css/wp-content/plugins/skittybop/assets/js/skittybop-admin.js/wp-content/plugins/skittybop/assets/js/skittybop.js/wp-content/plugins/skittybop/includes/skittybop-constants.php/wp-content/plugins/skittybop/includes/skittybop-functions.php/wp-content/plugins/skittybop/includes/skittybop-ajax.php
Script Paths
/wp-content/plugins/skittybop/assets/js/skittybop-admin.js/wp-content/plugins/skittybop/assets/js/skittybop.js
Version Parameters
skittybop/assets/css/skittybop-admin.css?ver=skittybop/assets/css/skittybop.css?ver=skittybop/assets/js/skittybop-admin.js?ver=skittybop/assets/js/skittybop.js?ver=

HTML / DOM Fingerprints

CSS Classes
skittybop-buttonskittybop-dialog
Data Attributes
data-skittybop-api-keydata-skittybop-nonce
JS Globals
skittybop_ajax_object
FAQ

Frequently Asked Questions about Skittybop