u2gg Security & Risk Analysis

wordpress.org/plugins/u2gg

Plug-in to display the date WAREKI(GENGOU).

10 active installs v0.2 PHP + WP 2.8.5+ Updated Jul 7, 2012
dategengouwareki
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is u2gg Safe to Use in 2026?

Generally Safe

Score 85/100

u2gg has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "u2gg" plugin v0.2 exhibits a strong adherence to fundamental WordPress security practices. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events, particularly those lacking authentication checks, indicates a very limited attack surface and a proactive approach to securing entry points. Furthermore, the complete avoidance of dangerous functions, file operations, and external HTTP requests contributes to a robust security posture. The fact that all SQL queries are properly prepared is also a significant positive, mitigating risks of SQL injection vulnerabilities.

However, a notable concern arises from the output escaping analysis. With one total output detected and 0% properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that is not properly escaped could be manipulated by attackers to inject malicious scripts. The lack of nonce and capability checks, while not directly leading to identified vulnerabilities in static analysis, indicates potential weaknesses if new entry points are introduced in future versions without proper security considerations. The clean vulnerability history is a positive sign, suggesting a history of secure development, but it does not negate the identified XSS risk in the current version.

In conclusion, while "u2gg" v0.2 demonstrates an excellent understanding of mitigating common attack vectors through a minimal attack surface and secure data handling for database operations, the unescaped output is a critical oversight. This single weakness significantly elevates the overall risk profile, as XSS vulnerabilities can have severe consequences. Addressing the output escaping is paramount for improving the plugin's security.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

u2gg Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

u2gg Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

u2gg Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

u2gg Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

u2gg Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedJul 7, 2012
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

u2gg Developer Profile

gosunatxrea

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect u2gg

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
平成昭和大正明治
FAQ

Frequently Asked Questions about u2gg