WP-Speech-Balloon Security & Risk Analysis

wordpress.org/plugins/wp-speech-balloon

WordPress の記事内で簡単に吹き出し会話を使えるプラグインです。AMPページでも通常ページと同じように吹き出し会話を使えます。 This is a plugin that makes it easy to use balloon conversation with WordPress.

400 active installs v2.4 PHP 5.2.4+ WP 4.9.4+ Updated Apr 11, 2019
balloonbubbleschatfukidashispeech-balloon
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-Speech-Balloon Safe to Use in 2026?

Generally Safe

Score 85/100

WP-Speech-Balloon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The wp-speech-balloon plugin, version 2.4, presents a generally strong security posture based on the provided static analysis. The absence of known CVEs, both current and historical, is a significant positive indicator. Furthermore, the code exhibits good practices with 100% of SQL queries using prepared statements and 100% of outputs being properly escaped, which are crucial for preventing common vulnerabilities like SQL injection and cross-site scripting (XSS). The plugin also correctly avoids external HTTP requests, reducing potential attack vectors.

However, there are a few areas that warrant attention. The presence of 24 shortcodes constitutes a substantial attack surface, even though the current analysis shows no unprotected entry points. While no specific vulnerabilities were identified in the taint analysis, the lack of explicit nonce and capability checks on these shortcodes, or potentially other entry points not detailed, could become a risk if the shortcode functionality ever handles user-supplied data without proper sanitization or authorization. The single file operation also warrants a closer look to ensure it is secure and doesn't expose any vulnerabilities.

In conclusion, wp-speech-balloon v2.4 appears to be a well-coded plugin with a good track record. Its adherence to prepared statements and output escaping is commendable. The main concern lies in the potential for vulnerabilities within the shortcode functionality, especially if it evolves to handle sensitive data without robust authorization and input validation mechanisms. The lack of explicit capability and nonce checks, despite the current lack of identified vulnerabilities, is a potential weakness that should be monitored, particularly in future updates.

Key Concerns

  • Large attack surface (shortcodes)
  • Missing nonce checks
  • Missing capability checks
  • Presence of file operations
Vulnerabilities
None known

WP-Speech-Balloon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP-Speech-Balloon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0
Attack Surface

WP-Speech-Balloon Attack Surface

Entry Points24
Unprotected0

Shortcodes 24

[L1_wsbStart] wp-speech-balloon.php:50
[L1_gray_wsbStart] wp-speech-balloon.php:54
[L2_wsbStart] wp-speech-balloon.php:58
[L2_gray_wsbStart] wp-speech-balloon.php:62
[L3_wsbStart] wp-speech-balloon.php:66
[L3_gray_wsbStart] wp-speech-balloon.php:70
[L4_wsbStart] wp-speech-balloon.php:74
[L5_wsbStart] wp-speech-balloon.php:78
[L_wsbAvatar] wp-speech-balloon.php:82
[L_wsbName] wp-speech-balloon.php:86
[L_wsbText] wp-speech-balloon.php:90
[L_wsbEnd] wp-speech-balloon.php:94
[R1_wsbStart] wp-speech-balloon.php:98
[R1_gray_wsbStart] wp-speech-balloon.php:102
[R2_wsbStart] wp-speech-balloon.php:106
[R2_gray_wsbStart] wp-speech-balloon.php:110
[R3_wsbStart] wp-speech-balloon.php:114
[R3_gray_wsbStart] wp-speech-balloon.php:118
[R4_wsbStart] wp-speech-balloon.php:122
[R5_wsbStart] wp-speech-balloon.php:126
[R_wsbText] wp-speech-balloon.php:130
[R_wsbAvatar] wp-speech-balloon.php:134
[R_wsbName] wp-speech-balloon.php:138
[R_wsbEnd] wp-speech-balloon.php:142
WordPress Hooks 3
actionafter_setup_themewp-speech-balloon.php:45
actionshutdownwp-speech-balloon.php:46
filterthe_contentwp-speech-balloon.php:167
Maintenance & Trust

WP-Speech-Balloon Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedApr 11, 2019
PHP min version5.2.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

WP-Speech-Balloon Developer Profile

RA's_Tips4Life

1 plugin · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP-Speech-Balloon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-speech-balloon/css/style.php
Version Parameters
wp-speech-balloon/css/style.php?ver=

HTML / DOM Fingerprints

CSS Classes
wsbwsb-lwsb-l1wsb-l2wsb-l3wsb-l4wsb-l5wsb-r+16 more
Data Attributes
alt="avatar"
Shortcode Output
<div class="wsb"><div class="wsb-l wsb-l1 "><div class="wsb"><div class="wsb-l wsb-l1-gray "><div class="wsb"><div class="wsb-l wsb-l2 "><div class="wsb"><div class="wsb-l wsb-l2-gray ">
FAQ

Frequently Asked Questions about WP-Speech-Balloon