Yahoo Messenger Online Status Security & Risk Analysis

wordpress.org/plugins/ym-online-status

Allows blog owners to show their Yahoo Messenger online status using their own status button.

10 active installs v0.3.1 PHP + WP 2.0+ Updated Dec 1, 2007
messengeronlinesidebarstatusyahoo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yahoo Messenger Online Status Safe to Use in 2026?

Generally Safe

Score 85/100

Yahoo Messenger Online Status has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 18yr ago
Risk Assessment

The "ym-online-status" v0.3.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any recorded vulnerabilities or CVEs in its history is a significant positive indicator. Furthermore, the code shows no dangerous functions, file operations, or external HTTP requests, and all SQL queries are properly prepared. This suggests a developer who is mindful of common security pitfalls.

However, the analysis also highlights a major concern: the complete lack of output escaping. With 40 total outputs analyzed, and 0% properly escaped, this represents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed by the plugin could potentially be exploited by an attacker to inject malicious scripts. Additionally, the absence of nonce and capability checks, while not directly resulting in an attack surface based on the provided metrics, indicates a potential weakness if new entry points were to be introduced in future versions.

In conclusion, while the plugin avoids many common security flaws and has a clean vulnerability history, the pervasive lack of output escaping presents a critical and easily exploitable vulnerability. This single issue significantly overshadows the otherwise positive aspects of the code. Rectifying the output escaping is paramount to improving the plugin's security.

Key Concerns

  • 0% output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Yahoo Messenger Online Status Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Yahoo Messenger Online Status Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
40
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped40 total outputs
Attack Surface

Yahoo Messenger Online Status Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionactivate_ym-online-status/ym_status.phpym_status.php:400
actiondeactivate_ym-online-status/ym_status.phpym_status.php:401
actioninitym_status.php:402
actionadmin_menuym_status.php:403
actionwidgets_initym_status.php:404
Maintenance & Trust

Yahoo Messenger Online Status Maintenance & Trust

Maintenance Signals

WordPress version tested2.3
Last updatedDec 1, 2007
PHP min version
Downloads36K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Yahoo Messenger Online Status Developer Profile

Huda Toriq

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yahoo Messenger Online Status

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ym-online-status/accept.png/wp-content/plugins/ym-online-status/error.png

HTML / DOM Fingerprints

CSS Classes
serverinfoserverinfo_error
Data Attributes
name="yahoo_id"name="button_title"name="ym_button_choice"
FAQ

Frequently Asked Questions about Yahoo Messenger Online Status