UserEcho for WordPress Security & Risk Analysis

wordpress.org/plugins/userecho

Integrate UserEcho - customer feedback and helpdesk system into your blog. Using widget or link. Support SSO.

10 active installs v1.0.29 PHP + WP 3.0+ Updated Jul 23, 2025
feedback-forumhelpdeskideaslivechatwidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is UserEcho for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

UserEcho for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "userecho" v1.0.29 plugin exhibits a generally strong security posture based on the provided static analysis. It has a remarkably small attack surface with no detected AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, none of these entry points appear unprotected. The code also demonstrates good practices by exclusively using prepared statements for its SQL queries and includes nonce and capability checks, indicating awareness of common WordPress security vulnerabilities. However, a significant concern arises from the taint analysis, which reveals one flow with an unsanitized path. While no critical or high severity issues were identified in the taint analysis, and the plugin has no recorded vulnerability history, this unsanitized path represents a potential entry point for attackers, even if its immediate impact is unclear without further investigation. The plugin also shows a moderate level of unescaped output, which, while not critical, could lead to cross-site scripting (XSS) vulnerabilities in certain contexts.

Key Concerns

  • Flow with unsanitized path found in taint analysis
  • Moderate percentage of unescaped output
Vulnerabilities
None known

UserEcho for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

UserEcho for WordPress Release Timeline

v1.0.29Current
v1.0.28
v1.0.27
v1.0.26
v1.0.25
v1.0.24
v1.0.23
v1.0.22
v1.0.21
v1.0.20
v1.0.19
v1.0.18
v1.0.17
v1.0.16
v1.0.15
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
Code Analysis
Analyzed Mar 16, 2026

UserEcho for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
24 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

51% escaped47 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
check_if_sso_login (userecho.php:407)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

UserEcho for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuuserecho.php:40
actionwp_footeruserecho.php:41
actionwidgets_inituserecho.php:459
filterlogin_redirectuserecho.php:545
Maintenance & Trust

UserEcho for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 23, 2025
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

UserEcho for WordPress Developer Profile

sstukov

2 plugins · 10 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect UserEcho for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/userecho/css/userecho_admin.css/wp-content/plugins/userecho/js/userecho_admin.js

HTML / DOM Fingerprints

CSS Classes
UserEcho_options
HTML Comments
UserEcho for Wordpress - collect feedback for your blogThis program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License, version 2, as published by the Free Software Foundation. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
Data Attributes
id="domain"name="domain"id="show_tab"name="show_tab"id="forum"name="forum"+20 more
JS Globals
UE_URL
FAQ

Frequently Asked Questions about UserEcho for WordPress