WP Emo-ello Security & Risk Analysis

wordpress.org/plugins/wp-emo-ello

Fontello Emoticons can be inserted using either HTML, shortcode or a built-in TinyMCE plugin. This plugin also replaces Wordpress' smileys.

10 active installs v0.3 PHP + WP 3.9.0+ Updated Unknown
emoticonsfontellosmileys
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Emo-ello Safe to Use in 2026?

Generally Safe

Score 100/100

WP Emo-ello has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'wp-emo-ello' plugin version 0.3 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of critical and high-severity taint flows, coupled with 100% proper output escaping and the use of prepared statements for all SQL queries, indicates a strong adherence to secure coding practices in these areas. Furthermore, the lack of any known CVEs, historical or current, suggests a history of reliable and secure development. The plugin's attack surface is minimal, with only one shortcode, and importantly, no unprotected entry points were identified through static analysis. The presence of capability checks and the inclusion of TinyMCE as a bundled library are also positive indicators of a thought-out implementation.

However, a notable concern arises from the complete absence of nonce checks. While the static analysis reports no unprotected entry points, nonce checks are a fundamental defense mechanism against Cross-Site Request Forgery (CSRF) attacks. Their omission, even with capability checks in place, leaves a potential gap in security that could be exploited under certain circumstances. Therefore, while the plugin is strong in many areas, the lack of nonce validation represents a significant, albeit potentially exploitable, weakness that should be addressed to achieve a truly robust security profile.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

WP Emo-ello Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Emo-ello Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

100% escaped2 total outputs
Attack Surface

WP Emo-ello Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[icon] wp-emo-ello.php:130
WordPress Hooks 12
filterthe_contentwp-emo-ello.php:119
filterthe_excerptwp-emo-ello.php:120
filterget_comment_textwp-emo-ello.php:121
filterget_comment_excerptwp-emo-ello.php:122
actionwp_enqueue_scriptswp-emo-ello.php:127
actionadmin_enqueue_scriptswp-emo-ello.php:128
actionadmin_initwp-emo-ello.php:129
filterwidget_textwp-emo-ello.php:131
filtermce_external_pluginswp-emo-ello.php:137
filtermce_buttonswp-emo-ello.php:138
filterteeny_mce_buttonswp-emo-ello.php:139
filtermce_csswp-emo-ello.php:140
Maintenance & Trust

WP Emo-ello Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.0
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Emo-ello Developer Profile

viphat

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Emo-ello

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-emo-ello/assets/css/fontello.css/wp-content/plugins/wp-emo-ello/assets/css/fontello-ie7.css
Script Paths
/wp-content/plugins/wp-emo-ello/assets/js/wp-emo-ello.js
Version Parameters
wp-emo-ello/assets/css/fontello.css?ver=wp-emo-ello/assets/css/fontello-ie7.css?ver=wp-emo-ello/assets/js/wp-emo-ello.js?ver=

HTML / DOM Fingerprints

CSS Classes
icon-emo-happyicon-emo-unhappyicon-emo-wink2icon-emo-tongueicon-emo-sleepicon-emo-thumbsupicon-emo-devilicon-emo-surprised+11 more
Data Attributes
data-icon
JS Globals
emo_ello
Shortcode Output
<i class="icon-
FAQ

Frequently Asked Questions about WP Emo-ello