Bikit Business Directory Security & Risk Analysis

wordpress.org/plugins/bikit-business-directory

Bikit Business Directory WordPress Plugin with innovative features, easy customization, and full compatibility with WP Directory Kit premium tools.

10 active installs v1.0.0 PHP 7.4+ WP 5.2+ Updated Dec 22, 2025
business-directorydirectorydirectory-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Bikit Business Directory Safe to Use in 2026?

Generally Safe

Score 100/100

Bikit Business Directory has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "bikit-business-directory" plugin v1.0.0 exhibits a concerning security posture primarily due to a significant unprotected attack surface. While the plugin demonstrates good practices by utilizing prepared statements for all its SQL queries and performing capability checks for some operations, the presence of three AJAX handlers without any authentication or capability checks is a major vulnerability. This means any unauthenticated user could potentially interact with these handlers, leading to unintended consequences or information disclosure if they are not properly secured internally. The absence of taint analysis flows is either indicative of a very small plugin or a lack of comprehensive static analysis. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign, suggesting it has been relatively secure thus far. However, this lack of history doesn't negate the immediate risks identified in the static analysis. The plugin's strengths lie in its SQL handling and some level of access control, but its weakness in securing its entry points is a critical oversight that needs immediate attention.

Key Concerns

  • AJAX handlers without auth checks
  • Limited output escaping (39% unescaped)
  • No nonce checks on AJAX handlers
Vulnerabilities
None known

Bikit Business Directory Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bikit Business Directory Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
22
34 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

61% escaped56 total outputs
Attack Surface
3 unprotected

Bikit Business Directory Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_bikibudi_admin_actionincludes\class-bikit-business-directory.php:177
authwp_ajax_bikibudi_public_actionincludes\class-bikit-business-directory.php:200
noprivwp_ajax_bikibudi_public_actionincludes\class-bikit-business-directory.php:206
WordPress Hooks 28
filterupload_mimesactions.php:8
actionwp_enqueue_scriptselementor-elements\elementor-init.php:221
actionwp_enqueue_scriptselementor-elements\elementor-init.php:222
actionelementor/elements/categories_registeredelementor-elements\elementor-init.php:224
actionelementor/widgets/registerelementor-elements\elementor-init.php:225
actionelementor/initelementor-elements\elementor-init.php:238
filterwdk/settings/import/multipurpose_valuesextensions\theme-bikit.php:19
filterwdk/settings/import/run/fieldsextensions\theme-bikit.php:20
filterwdk/settings/import/run/postextensions\theme-bikit.php:21
filterwdk/settings/import/run/import_images_dirextensions\theme-bikit.php:22
filterwdk/settings/import/run/import_xml_fileextensions\theme-bikit.php:23
filterwdk/settings/import/run/import_xml_file_locationsextensions\theme-bikit.php:24
actionwdk/settings/import/runextensions\theme-bikit.php:25
actionwdk/settings/import/api_runextensions\theme-bikit.php:26
filterwdk/settings/import/api_run/import_images_dirextensions\theme-bikit.php:27
filterwdk/settings/import/api_run/import_xml_fileextensions\theme-bikit.php:28
filterwdk/settings/import/api_run/import_xml_file_locationsextensions\theme-bikit.php:29
filterwdk/settings/import/run/info_log_messageextensions\theme-bikit.php:30
actionwpdirectorykit/elementor-elements/register_widgetextensions\theme-bikit.php:94
actionwpdirectorykit/elementor-elements/register_widgetextensions\theme-bikit.php:119
filterplugin_action_links_bikit-business-directory/bikit-business-directory.phpfilters.php:7
actionadmin_enqueue_scriptsincludes\class-bikit-business-directory.php:165
actionadmin_enqueue_scriptsincludes\class-bikit-business-directory.php:166
actionadmin_menuincludes\class-bikit-business-directory.php:171
actionwp_enqueue_scriptsincludes\class-bikit-business-directory.php:196
actionwp_enqueue_scriptsincludes\class-bikit-business-directory.php:197
actionplugins_loadedincludes\class-bikit-business-directory.php:257
filterajax_query_attachments_argsincludes\class-bikit-business-directory.php:275
Maintenance & Trust

Bikit Business Directory Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 22, 2025
PHP min version7.4
Downloads234

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Bikit Business Directory Developer Profile

WPDirectoryKit

6 plugins · 4K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
101 days
View full developer profile
Detection Fingerprints

How We Detect Bikit Business Directory

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bikit-business-directory/admin/css/bikit-business-directory-admin.css/wp-content/plugins/bikit-business-directory/admin/css/bikit-business-directory-admin-responsive.css/wp-content/plugins/bikit-business-directory/elementor-elements/assets/css/bikit-business-directory-main.css
Script Paths
/wp-content/plugins/bikit-business-directory/admin/js/bikit-business-directory-admin.js
Version Parameters
bikit-business-directory/admin/css/bikit-business-directory-admin.css?ver=bikit-business-directory/admin/css/bikit-business-directory-admin-responsive.css?ver=bikit-business-directory-elementor-main?ver=bikit-business-directory/admin/js/bikit-business-directory-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
bikit-business-directory-import
JS Globals
bikibudi_script_parameters
FAQ

Frequently Asked Questions about Bikit Business Directory