Best Listing Toolkit Security & Risk Analysis

wordpress.org/plugins/best-listing-toolkit

A necessary toolkit created by https://www.wpwax.com for the Best Listing Theme. Custom elementor widgets and theme widgets are some of the new featur …

200 active installs v1.2 PHP 7.0+ WP 5.0+ Updated Jan 25, 2023
best-listingclassifiedsdirectoristlistingmigration-to-new-theme
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Best Listing Toolkit Safe to Use in 2026?

Generally Safe

Score 85/100

Best Listing Toolkit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The static analysis of the "best-listing-toolkit" plugin v1.2 reveals a generally strong security posture based on the provided metrics. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing the potential attack surface. The code signals also indicate good practices, with no dangerous functions, no file operations, no external HTTP requests, and all SQL queries utilizing prepared statements. Furthermore, the high percentage of properly escaped output (89%) is a positive indicator of secure coding. The absence of any known vulnerabilities in its history is also a testament to its current security standing.

However, the complete absence of nonce checks and capability checks across all entry points (which are zero in this analysis) is a significant concern, even with the limited attack surface. While there are no identified flows from the taint analysis or specific vulnerabilities in the history, a future expansion of the plugin's features or the introduction of new entry points without these fundamental security mechanisms could lead to severe security flaws. The limited data on taint analysis and the lack of any identified entry points mean that the true robustness of sanitization and authorization mechanisms in potential future attack vectors remains untested.

In conclusion, the plugin currently exhibits strong defensive coding practices, particularly regarding SQL injection and output sanitization. The lack of historical vulnerabilities is encouraging. The primary weakness lies in the absence of fundamental security controls like nonces and capability checks, which, while not posing an immediate threat given the current minimal attack surface, represents a notable area for improvement should the plugin evolve. It's crucial to maintain this secure foundation as new features are added.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Limited taint analysis data
  • Percentage of unescaped output (11%)
Vulnerabilities
None known

Best Listing Toolkit Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Best Listing Toolkit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
281 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped315 total outputs
Attack Surface

Best Listing Toolkit Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedbest-listing-toolkit.php:28
actionbest_listing_init_afterbest-listing-toolkit.php:29
actionelementor/editor/after_enqueue_styleselementor-support\init.php:26
actionelementor/elements/categories_registeredelementor-support\init.php:27
actionelementor/widgets/registerelementor-support\init.php:28
actionelementor/widgets/registerelementor-support\init.php:29
filterbest_listing_elementor_settings_dataelementor-support\search-listing\class.php:360
actionadmin_footerwidgets\base.php:13
actionwidgets_initwidgets\init.php:35
Maintenance & Trust

Best Listing Toolkit Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJan 25, 2023
PHP min version7.0
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Best Listing Toolkit Developer Profile

wpWax

15 plugins · 62K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
210 days
View full developer profile
Detection Fingerprints

How We Detect Best Listing Toolkit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/best-listing-toolkit/assets/css/main.css/wp-content/plugins/best-listing-toolkit/assets/js/main.js/wp-content/plugins/best-listing-toolkit/elementor-support/assets/css/elementor-widget.css
Script Paths
/wp-content/plugins/best-listing-toolkit/assets/js/main.js
Version Parameters
best-listing-toolkit/assets/css/main.css?ver=best-listing-toolkit/assets/js/main.js?ver=best-listing-toolkit/elementor-support/assets/css/elementor-widget.css?ver=

HTML / DOM Fingerprints

CSS Classes
theme-rowtheme-blog-eachtheme-blog-cardblog-grid-cardtheme-blog-card__thumbnailtheme-blog-card__detailstheme-blog-card__contenttheme-blog-card__title+19 more
HTML Comments
<!-- @author wpWax --><!-- @since 1.0 --><!-- @version 1.0 --><!-- Only for Listing details page. -->
Data Attributes
data-widget_typedata-element_type
JS Globals
wpWaxHelper
Shortcode Output
<div class="atbdp atbd_author_info_widget">
FAQ

Frequently Asked Questions about Best Listing Toolkit