Zodan Text Upfunker Security & Risk Analysis

wordpress.org/plugins/z-text-upfunker

Funking up your texts by selecting html elements in your theme and assigning animation styles.

0 active installs v1.1.1 PHP + WP 5.5+ Updated Jan 12, 2026
animationdevelopmenttexttheme-designtheme-development
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zodan Text Upfunker Safe to Use in 2026?

Generally Safe

Score 100/100

Zodan Text Upfunker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "z-text-upfunker" v1.1.1 plugin exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The complete absence of identified attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events is a significant positive. Furthermore, the code signals indicate a healthy approach to SQL queries, with 100% using prepared statements, and a reasonable 75% of output escaping, suggesting an effort to prevent cross-site scripting (XSS) vulnerabilities. The lack of file operations, external HTTP requests, and taint analysis findings also contributes to a low-risk profile. The vulnerability history being entirely clean, with no recorded CVEs, further reinforces this perception of a secure plugin. However, the absence of any nonce checks or capability checks, despite the presence of 79 output points, is a notable weakness. While no direct vulnerabilities are flagged by the analysis, these missing security mechanisms could potentially be exploited if an attack vector were to be discovered or introduced in future versions. In conclusion, the plugin demonstrates good practices in many areas, particularly concerning SQL and external interactions, but the lack of explicit authorization and nonce checks presents a potential area for improvement and future risk.

Key Concerns

  • Missing nonce checks on outputs
  • Missing capability checks on outputs
  • Partially unescaped output
Vulnerabilities
None known

Zodan Text Upfunker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Zodan Text Upfunker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
59 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped79 total outputs
Attack Surface

Zodan Text Upfunker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedz-text-upfunker.php:29
actionsetup_themez-text-upfunker.php:34
actionadmin_enqueue_scriptsz-text-upfunker.php:62
actionadmin_initz-text-upfunker.php:63
actionadmin_menuz-text-upfunker.php:64
actionwp_enqueue_scriptsz-text-upfunker.php:74
filteradmin_footer_textz-text-upfunker.php:442
Maintenance & Trust

Zodan Text Upfunker Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 12, 2026
PHP min version
Downloads998

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Zodan Text Upfunker Developer Profile

martenmoolenaar

6 plugins · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zodan Text Upfunker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/z-text-upfunker/assets/z-text-upfunker.min.css/wp-content/plugins/z-text-upfunker/assets/z-text-upfunker.min.js
Script Paths
/wp-content/plugins/z-text-upfunker/assets/z-text-upfunker.min.js
Version Parameters
z-text-upfunker/assets/z-text-upfunker.min.css?ver=z-text-upfunker/assets/z-text-upfunker.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
introz-tu-helpia_items
Data Attributes
data-elemdata-typedata-cyclesdata-charspeeddata-cyclespeed
JS Globals
zodanTextUpfunkerParams
FAQ

Frequently Asked Questions about Zodan Text Upfunker