Alley Business Toolkit Security & Risk Analysis

wordpress.org/plugins/alley-business-toolkit

Alley Business Tootkit help you to create post types that needed for any business.

100 active installs v2.0.7 PHP + WP 5.6+ Updated Sep 18, 2024
businesspromtionsservices
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Alley Business Toolkit Safe to Use in 2026?

Generally Safe

Score 92/100

Alley Business Toolkit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "alley-business-toolkit" v2.0.7 plugin exhibits a generally good security posture with several positive indicators. The absence of known vulnerabilities, including critical and high severity ones, is a strong positive. The code analysis shows a complete lack of dangerous functions and raw SQL queries, with all SQL queries utilizing prepared statements, indicating robust database interaction practices. Additionally, the plugin performs file operations and makes external HTTP requests, further demonstrating secure coding practices in these sensitive areas. The presence of nonce and capability checks also suggests an awareness of WordPress security best practices.

However, a significant concern arises from the static analysis regarding the plugin's attack surface. It has one identified AJAX handler that lacks authentication checks. This unprotected entry point is a potential vector for exploitation, as it could allow unauthenticated users to trigger actions within the plugin. While the taint analysis shows no issues, this unprotected AJAX handler still poses a risk. The output escaping, while having a majority of outputs properly escaped, still has a notable percentage (34%) that are not, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved.

In conclusion, the plugin's history of no vulnerabilities and its strong adherence to secure practices like prepared statements and absence of dangerous functions are commendable. However, the single unprotected AJAX handler is a critical weakness that needs immediate attention. The less-than-perfect output escaping also presents a moderate risk. Addressing the unprotected AJAX handler and improving output escaping would significantly enhance the plugin's security.

Key Concerns

  • AJAX handler without authentication
  • Significant percentage of unescaped output
Vulnerabilities
None known

Alley Business Toolkit Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Alley Business Toolkit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
44
87 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

66% escaped131 total outputs
Attack Surface
1 unprotected

Alley Business Toolkit Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_alley_business_toolkit_getting_startedincludes\class-alley-business-toolkit.php:165
WordPress Hooks 27
actionwidgets_initadmin\abt-widgets.php:70
actioninitadmin\class-custom-posttype.php:58
actioninitadmin\class-custom-posttype.php:60
actioncustomize_registeradmin\customizer\customizer.php:7
actionwp_headadmin\functions.php:138
actionwp_footeradmin\functions.php:150
actionadvanced_import_is_pro_activeadmin\functions.php:165
actionadmin_initadmin\metabox\add-metabox.php:6
actionsave_postadmin\metabox\save-metabox.php:3
actionadmin_noticesadmin\partials\admin-notice.php:58
actionadmin_initadmin\partials\admin-notice.php:73
actionadmin_menuadmin\register-menu.php:14
actionadmin_menuadmin\register-menu.php:17
actionadmin_menuadmin\register-menu.php:18
actionadmin_menuadmin\register-menu.php:19
actionactivated_pluginalley-business-toolkit.php:37
actionpre_current_active_pluginsalley-business-toolkit.php:38
actionafter_uninstallalley-business-toolkit.php:169
actionplugins_loadedincludes\class-alley-business-toolkit.php:154
actionadmin_initincludes\class-alley-business-toolkit.php:162
actionadvanced_import_demo_listsincludes\class-alley-business-toolkit.php:163
actionadmin_menuincludes\class-alley-business-toolkit.php:164
actionadmin_enqueue_scriptsincludes\class-alley-business-toolkit.php:166
actionadmin_initincludes\class-alley-business-toolkit.php:167
actionwp_enqueue_scriptsincludes\class-alley-business-toolkit.php:199
actionwp_enqueue_scriptsincludes\class-alley-business-toolkit.php:200
actionadmin_noticesincludes\class-alley-business-toolkit.php:228
Maintenance & Trust

Alley Business Toolkit Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 18, 2024
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Alley Business Toolkit Developer Profile

alleythemes

4 plugins · 630 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Alley Business Toolkit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/alley-business-toolkit/admin/js/alley-business-toolkit-admin.js/wp-content/plugins/alley-business-toolkit/admin/css/alley-business-toolkit-admin.css/wp-content/plugins/alley-business-toolkit/public/css/alley-business-toolkit-public.css/wp-content/plugins/alley-business-toolkit/public/js/alley-business-toolkit-public.js
Script Paths
/wp-content/plugins/alley-business-toolkit/admin/js/alley-business-toolkit-admin.js/wp-content/plugins/alley-business-toolkit/public/js/alley-business-toolkit-public.js/wp-content/plugins/alley-business-toolkit/freemius/start.php
Version Parameters
alley-business-toolkit/admin/js/alley-business-toolkit-admin.js?ver=alley-business-toolkit/admin/css/alley-business-toolkit-admin.css?ver=alley-business-toolkit/public/css/alley-business-toolkit-public.css?ver=alley-business-toolkit/public/js/alley-business-toolkit-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
alley-business-toolkit-plugin
Data Attributes
data-slug="alley-business-toolkit"data-premium-slug="alley-business-toolkit-pro"
JS Globals
abt_fs
FAQ

Frequently Asked Questions about Alley Business Toolkit