
Word Balloon Security & Risk Analysis
wordpress.org/plugins/word-balloonSupport for Block editor(Gutenberg) & Classic Editor.You will easy to add speech balloon in your post.
Is Word Balloon Safe to Use in 2026?
Generally Safe
Score 97/100Word Balloon has a strong security track record. Known vulnerabilities have been patched promptly.
The 'word-balloon' plugin v4.23.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices in output escaping, with 96% of outputs properly handled, and a strong emphasis on nonce checks and capability checks, indicating an awareness of common WordPress security vulnerabilities. The absence of file operations and external HTTP requests further mitigates certain risk vectors. However, the presence of one unprotected AJAX handler represents a significant concern, as it could be exploited by unauthenticated users to trigger plugin functionality. Additionally, the vulnerability history of this plugin is a notable weakness, with three past CVEs, including one high-severity vulnerability related to Remote File Inclusion. This history, coupled with the current unprotected entry point, suggests a recurring pattern of security oversight that requires attention.
Key Concerns
- Unprotected AJAX handler detected
- Past high severity vulnerability (RFI)
- Past medium severity vulnerabilities (CSRF, XSS)
- SQL queries partially un-prepared
- Taint flows with unsanitized paths
Word Balloon Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Word Balloon <= 4.21.1 - Authenticated (Contributor+) Local File Inclusion
Word Balloon <= 4.20.2 - Cross-Site Request Forgery
Word Balloon <= 4.19.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Word Balloon Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Word Balloon Attack Surface
AJAX Handlers 2
Shortcodes 6
WordPress Hooks 22
Maintenance & Trust
Word Balloon Maintenance & Trust
Maintenance Signals
Community Trust
Word Balloon Alternatives
WP-Speech-Balloon
wp-speech-balloon
WordPress の記事内で簡単に吹き出し会話を使えるプラグインです。AMPページでも通常ページと同じように吹き出し会話を使えます。 This is a plugin that makes it easy to use balloon conversation with WordPress.
Speech Balloon Maker (ふきだしメーカー)
speech-balloon-maker
You can make speech balloon as you like.
Conversation Viewer – Display Chat Bubbles
conversation-viewer-display-chat-bubbles
A plugin for displaying chat bubbles on your site, like in their original messaging apps.
Guten-bubble
guten-bubble
Displays a speech bubble like a chat conversation.
Hinagata Speech Balloon
hinagata-speech-balloon
Adds a highly customizable "Speech Balloon" block to the WordPress editor. Allows creating presets with avatars and inserting them as blocks.
Word Balloon Developer Profile
5 plugins · 72K total installs
How We Detect Word Balloon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/word-balloon/css/word_balloon_user.min.css/wp-content/plugins/word-balloon/js/word_balloon_block.min.js/wp-content/plugins/word-balloon/js/word_balloon_block.min.jsword-balloon/css/word_balloon_user.min.css?ver=word-balloon/js/word_balloon_block.min.js?ver=HTML / DOM Fingerprints
data-word-balloon-blockword_balloon_block_balloonword_balloon_block_iconword_balloon_block_icon_positionword_balloon_block_effectword_balloon_block_filterword_balloon_block_in_view+4 more