Big Boom Directory Security & Risk Analysis

wordpress.org/plugins/big-boom-directory

Directory management system based on Custom Post Types, Taxonomies, and Fields

100 active installs v2.5.2 PHP + WP 3.5+ Updated Oct 18, 2025
custom-fieldscustom-post-typedirectorypost-typetaxonomy
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 2, 2025
Download
Safety Verdict

Is Big Boom Directory Safe to Use in 2026?

Generally Safe

Score 99/100

Big Boom Directory has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 2, 2025Updated 5mo ago
Risk Assessment

The plugin "big-boom-directory" v2.5.2 exhibits a generally strong security posture based on the static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events with exposed entry points suggests a limited attack surface. Crucially, the code demonstrates good security practices by having no dangerous functions, 100% of SQL queries using prepared statements, and 100% of output being properly escaped. The lack of file operations and external HTTP requests further reduces potential exposure.

However, the vulnerability history presents a significant concern. With one known CVE, specifically a medium-severity Cross-Site Scripting (XSS) vulnerability last patched on 2025-04-02, it indicates that the plugin has had security flaws in the past. While this specific vulnerability is currently patched, the presence of a past XSS issue, even if medium, suggests that developer attention to input sanitization and output escaping might not always be consistently applied, despite the positive findings in the static analysis for this version. The absence of capability checks and nonce checks across any identified entry points (though there are none) is a minor concern in theory, but practically, the lack of entry points mitigates this immediate risk.

In conclusion, while v2.5.2 of "big-boom-directory" appears to be well-secured in its current implementation, the historical presence of an XSS vulnerability warrants vigilance. Users should ensure they are always running the latest patched version and be aware that past security issues, even if resolved, can sometimes indicate a propensity for such vulnerabilities to reappear in future updates if coding practices aren't rigorously maintained. The plugin's strengths lie in its clean static analysis for this version, but its weakness is its historical vulnerability.

Key Concerns

  • Medium severity XSS vulnerability historically present
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
1

Big Boom Directory Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-13673medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Big Boom Directory <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 2, 2025 Patched in 2.5.1 (1d)
Code Analysis
Analyzed Mar 16, 2026

Big Boom Directory Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

100% escaped2 total outputs
Attack Surface

Big Boom Directory Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitbig-boom-directory.php:46
actionpre_get_postsbig-boom-directory.php:47
actionwidgets_initbig-boom-directory.php:48
actionupdated_postmetabig-boom-directory.php:53
actionsave_postbig-boom-directory.php:54
actiondelete_postbig-boom-directory.php:55
actionwpbig-boom-directory.php:85
Maintenance & Trust

Big Boom Directory Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 18, 2025
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Big Boom Directory Developer Profile

bigboomdesign

4 plugins · 220 total installs

92
trust score
Avg Security Score
89/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Big Boom Directory

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/big-boom-directory/assets/cmb2/js/select2/select2.min.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/colorpicker.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/datetimepicker.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/igrid.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/select.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/select2/select2.css/wp-content/plugins/big-boom-directory/assets/cmb2/js/media.js/wp-content/plugins/big-boom-directory/assets/cmb2/js/bootstrap-datetimepicker.min.js+27 more
Script Paths
/wp-content/plugins/big-boom-directory/lib/class-bbd.php/wp-content/plugins/big-boom-directory/lib/admin/class-bbd-admin.php/wp-content/plugins/big-boom-directory/assets/cmb2/init.php/wp-content/plugins/big-boom-directory/lib/admin/class-bbd-meta-boxes.php/wp-content/plugins/big-boom-directory/lib/class-bbd-view.php

HTML / DOM Fingerprints

CSS Classes
bbd-successbbd-fail
Data Attributes
data-bbd-post-id
JS Globals
bbd_viewBBD
FAQ

Frequently Asked Questions about Big Boom Directory