
Big Boom Directory Security & Risk Analysis
wordpress.org/plugins/big-boom-directoryDirectory management system based on Custom Post Types, Taxonomies, and Fields
Is Big Boom Directory Safe to Use in 2026?
Generally Safe
Score 99/100Big Boom Directory has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "big-boom-directory" v2.5.2 exhibits a generally strong security posture based on the static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events with exposed entry points suggests a limited attack surface. Crucially, the code demonstrates good security practices by having no dangerous functions, 100% of SQL queries using prepared statements, and 100% of output being properly escaped. The lack of file operations and external HTTP requests further reduces potential exposure.
However, the vulnerability history presents a significant concern. With one known CVE, specifically a medium-severity Cross-Site Scripting (XSS) vulnerability last patched on 2025-04-02, it indicates that the plugin has had security flaws in the past. While this specific vulnerability is currently patched, the presence of a past XSS issue, even if medium, suggests that developer attention to input sanitization and output escaping might not always be consistently applied, despite the positive findings in the static analysis for this version. The absence of capability checks and nonce checks across any identified entry points (though there are none) is a minor concern in theory, but practically, the lack of entry points mitigates this immediate risk.
In conclusion, while v2.5.2 of "big-boom-directory" appears to be well-secured in its current implementation, the historical presence of an XSS vulnerability warrants vigilance. Users should ensure they are always running the latest patched version and be aware that past security issues, even if resolved, can sometimes indicate a propensity for such vulnerabilities to reappear in future updates if coding practices aren't rigorously maintained. The plugin's strengths lie in its clean static analysis for this version, but its weakness is its historical vulnerability.
Key Concerns
- Medium severity XSS vulnerability historically present
- No nonce checks detected
- No capability checks detected
Big Boom Directory Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Big Boom Directory <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Big Boom Directory Code Analysis
Bundled Libraries
Output Escaping
Big Boom Directory Attack Surface
WordPress Hooks 7
Maintenance & Trust
Big Boom Directory Maintenance & Trust
Maintenance Signals
Community Trust
Big Boom Directory Alternatives
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
Sydney Toolbox
sydney-toolbox
Registers custom post types and custom fields for the Sydney theme
Essential Content Types
essential-content-types
Essential Content Types allows you to feature the impressive content through different content/post types on your website just the way you want it.
Big Boom Directory Developer Profile
4 plugins · 220 total installs
How We Detect Big Boom Directory
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/big-boom-directory/assets/cmb2/js/select2/select2.min.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/colorpicker.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/datetimepicker.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/igrid.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/select.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/select2/select2.css/wp-content/plugins/big-boom-directory/assets/cmb2/js/media.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/bootstrap-datetimepicker.min.js+27 more/wp-content/plugins/big-boom-directory/lib/class-bbd.php/wp-content/plugins/big-boom-directory/lib/admin/class-bbd-admin.php/wp-content/plugins/big-boom-directory/assets/cmb2/init.php/wp-content/plugins/big-boom-directory/lib/admin/class-bbd-meta-boxes.php/wp-content/plugins/big-boom-directory/lib/class-bbd-view.phpHTML / DOM Fingerprints
bbd-successbbd-faildata-bbd-post-idbbd_viewBBD