WP30 By Who Security & Risk Analysis

wordpress.org/plugins/wp30-by-who

"WP30 By Who" is a simple add-on that enable a small bar for label "Designed by" and social media icons links at the bottom.

0 active installs v1.0.0 PHP + WP 3.3+ Updated Dec 16, 2017
barfollowfootersocialstarter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP30 By Who Safe to Use in 2026?

Generally Safe

Score 85/100

WP30 By Who has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "wp30-by-who" v1.0.0 exhibits a very strong security posture based on the provided static analysis and vulnerability history. The absence of any identified entry points, dangerous functions, raw SQL queries, file operations, external HTTP requests, or taint flows suggests a meticulously crafted codebase that adheres to best security practices. Furthermore, the lack of any known vulnerabilities in its history reinforces this positive outlook, indicating a well-maintained and secure plugin.

However, a critical area of concern is the significantly low percentage of properly escaped output (21%). This indicates a high risk of cross-site scripting (XSS) vulnerabilities. While the static analysis did not detect specific XSS flows, the sheer volume of unescaped output presents a substantial attack surface for privilege escalation and user data compromise. The absence of nonce and capability checks, while not directly flagged as critical in this instance due to the lack of exposed entry points, represents a missed opportunity for robust authorization, which could become a weakness if the plugin's attack surface were to expand in future versions.

In conclusion, the plugin demonstrates excellent security by avoiding common pitfalls like raw SQL and external requests. The primary weakness lies in the inadequate output escaping, which requires immediate attention. The clean vulnerability history is a significant strength, but it should not overshadow the critical need to address the output sanitization issues.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

WP30 By Who Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP30 By Who Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

21% escaped34 total outputs
Attack Surface

WP30 By Who Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionplugins_loadedincludes\class-wp30-by-who.php:142
actionadmin_enqueue_scriptsincludes\class-wp30-by-who.php:158
actionadmin_enqueue_scriptsincludes\class-wp30-by-who.php:159
actionadmin_menuincludes\class-wp30-by-who.php:161
actionadmin_initincludes\class-wp30-by-who.php:162
actionadmin_initincludes\class-wp30-by-who.php:163
actionadmin_initincludes\class-wp30-by-who.php:164
actionwp_enqueue_scriptsincludes\class-wp30-by-who.php:179
actionwp_enqueue_scriptsincludes\class-wp30-by-who.php:180
actionwp_footerincludes\class-wp30-by-who.php:182
Maintenance & Trust

WP30 By Who Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.0
Last updatedDec 16, 2017
PHP min version
Downloads989

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WP30 By Who Developer Profile

terrytsang

8 plugins · 1K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP30 By Who

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp30-by-who/css/wp30-by-who-admin.css/wp-content/plugins/wp30-by-who/js/wp30-by-who-admin.js
Script Paths
/wp-content/plugins/wp30-by-who/js/wp30-by-who-admin.js
Version Parameters
wp30-by-who/css/wp30-by-who-admin.css?ver=wp30-by-who/js/wp30-by-who-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP30 By Who