Speech Balloon Maker (ふきだしメーカー) Security & Risk Analysis

wordpress.org/plugins/speech-balloon-maker

You can make speech balloon as you like.

200 active installs v1.0.6 PHP 5.2.4+ WP 4.9+ Updated Apr 29, 2019
balloonbubblefukidashispeech-balloonspeech-bubble
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Speech Balloon Maker (ふきだしメーカー) Safe to Use in 2026?

Generally Safe

Score 85/100

Speech Balloon Maker (ふきだしメーカー) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "speech-balloon-maker" plugin version 1.0.6 exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and SQL queries executed without prepared statements are significant strengths. Furthermore, the lack of any recorded vulnerabilities in its history is encouraging, suggesting good development practices. However, a key area of concern is the low percentage of properly escaped output (24%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without adequate sanitization. The absence of nonce checks and capability checks on the identified entry points (shortcodes) is also a weakness, as it means these shortcodes might be exploitable by unauthenticated or low-privileged users in certain scenarios, depending on what they process and display. Despite these areas for improvement, the plugin's lack of critical flaws in taint analysis and its overall clean history present a relatively low immediate risk.

Key Concerns

  • Low output escaping percentage
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Speech Balloon Maker (ふきだしメーカー) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Speech Balloon Maker (ふきだしメーカー) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
39
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

24% escaped51 total outputs
Attack Surface

Speech Balloon Maker (ふきだしメーカー) Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[fuki-l] plugin.php:49
[balloon-l] plugin.php:50
[fuki-r] plugin.php:51
[balloon-r] plugin.php:52
WordPress Hooks 5
actionplugins_loadedplugin.php:44
actionadmin_menuplugin.php:45
actionwp_enqueue_scriptsplugin.php:46
actionadmin_initplugin.php:47
actionadmin_print_footer_scriptsplugin.php:55
Maintenance & Trust

Speech Balloon Maker (ふきだしメーカー) Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 29, 2019
PHP min version5.2.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Speech Balloon Maker (ふきだしメーカー) Developer Profile

Densuke

2 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Speech Balloon Maker (ふきだしメーカー)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/speech-balloon-maker/styles/dn_sbm_setting_style.css/wp-content/plugins/speech-balloon-maker/scripts/dn_sbm_script.js/wp-content/plugins/speech-balloon-maker/styles/dn_sbm_balloon_style.css
Script Paths
scripts/dn_sbm_script.js

HTML / DOM Fingerprints

CSS Classes
dn_sbm_balloon
Data Attributes
name="dn_sbm_leftside_icon_select_btn"name="dn_sbm_rightside_icon_select_btn"
JS Globals
dn_sbm_baloonmakerclass
Shortcode Output
[fuki-l][balloon-l][fuki-r][balloon-r]
FAQ

Frequently Asked Questions about Speech Balloon Maker (ふきだしメーカー)