
WP LetterPot Security & Risk Analysis
wordpress.org/plugins/wp-letterpotこのプラグインは、LetterPot (https://letterpot.otogimachi.jp/)のマイページの記事中に表示できるショートコードを提供します。
Is WP LetterPot Safe to Use in 2026?
Generally Safe
Score 85/100WP LetterPot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-letterpot v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent adherence to best practices by utilizing prepared statements for all SQL queries and performing a nonce check for its single entry point. The absence of dangerous functions, file operations, and reported critical or high severity taint flows further contributes to its secure design. Furthermore, a clean vulnerability history with zero known CVEs indicates a lack of past security incidents, suggesting diligent maintenance or a low target profile.
However, a significant concern arises from the low percentage of properly escaped output (15%). This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered without sufficient sanitization. While the attack surface is minimal and protected, and there are no unauthenticated entry points, the unescaped output is a critical weakness that could be exploited. The single external HTTP request, while not inherently risky, should be monitored for potential vulnerabilities if the target URL or its content is untrusted.
In conclusion, wp-letterpot v1.0.1 has strengths in its secure handling of SQL, minimal attack surface, and clean vulnerability history. However, the prevalent lack of output escaping is a major security flaw that overshadows these positives and requires immediate attention to mitigate XSS risks. Addressing this output escaping issue would significantly improve the plugin's overall security.
Key Concerns
- Low percentage of properly escaped output (15%)
WP LetterPot Security Vulnerabilities
WP LetterPot Release Timeline
WP LetterPot Code Analysis
SQL Query Safety
Output Escaping
WP LetterPot Attack Surface
Shortcodes 1
WordPress Hooks 5
Scheduled Events 1
Maintenance & Trust
WP LetterPot Maintenance & Trust
Maintenance Signals
Community Trust
WP LetterPot Alternatives
No alternatives data available yet.
WP LetterPot Developer Profile
10 plugins · 54K total installs
How We Detect WP LetterPot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-letterpot/assets/css/styles.min.css/wp-content/plugins/wp-letterpot/assets/js/validation/languages/jquery.validationEngine-ja.js/wp-content/plugins/wp-letterpot/assets/js/validation/jquery.validationEngine.js/wp-content/plugins/wp-letterpot/assets/js/formValidate.js/wp-content/plugins/wp-letterpot/assets/css/validationEngine.jquery.css/wp-content/plugins/wp-letterpot/assets/js/validation/languages/jquery.validationEngine-ja.js/wp-content/plugins/wp-letterpot/assets/js/validation/jquery.validationEngine.js/wp-content/plugins/wp-letterpot/assets/js/formValidate.jsHTML / DOM Fingerprints
user-infousernamethumbnailamount-listsid="wrap-main"[LetterPot]