
Boo Recipes Security & Risk Analysis
wordpress.org/plugins/boo-recipesEasily add Recipes in user friendly way that generates SEO optimized recipes using Schema.org microdata.
Is Boo Recipes Safe to Use in 2026?
Use With Caution
Score 64/100Boo Recipes has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "boo-recipes" plugin version 2.4.1 exhibits a mixed security posture. While it demonstrates good practices such as 100% prepared SQL statements and a reasonable number of nonce and capability checks, there are significant areas of concern. The presence of three AJAX handlers without authentication checks represents a substantial attack surface. Furthermore, the static analysis indicates that only 47% of output is properly escaped, raising the risk of Cross-Site Scripting (XSS) vulnerabilities. The single taint flow with an unsanitized path, although not classified as critical or high, warrants attention as it suggests potential for path traversal or similar issues if exploited.
The plugin's vulnerability history, specifically a medium severity CVE related to XSS discovered in April 2025 and remaining unpatched, is a major red flag. This indicates a pattern of potential security weaknesses that may not be promptly addressed. The combination of unprotected entry points, imperfect output escaping, and an existing unpatched vulnerability suggests that users of this plugin are at a notable risk, particularly from XSS attacks and potentially unauthorized actions via unprotected AJAX endpoints.
Key Concerns
- Unpatched CVE (Medium Severity)
- AJAX handlers without auth checks (3)
- Low percentage of properly escaped output (47%)
- Taint flow with unsanitized path (1)
Boo Recipes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Boo Recipes <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Boo Recipes Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Boo Recipes Attack Surface
AJAX Handlers 3
Shortcodes 3
WordPress Hooks 79
Maintenance & Trust
Boo Recipes Maintenance & Trust
Maintenance Signals
Community Trust
Boo Recipes Alternatives
WP Recipe Maker
wp-recipe-maker
The easy and user-friendly recipe plugin for everyone. Automatic JSON-LD metadata for food AND how-to recipes will improve your SEO!
Schema
schema
Get the next generation of Schema Structured Data to enhance your WordPress site presentation in Google search results.
Recipe Card Blocks Lite
recipe-card-blocks-by-wpzoom
Recipe Card Blocks with Schema Markup — create SEO-optimized recipes with Gutenberg, Elementor & AMP support
FAQ Schema For Pages And Posts
faq-schema-for-pages-and-posts
FAQ Schema For Pages And Posts by Krystian Szastok Founder of RobotZebra - a London based SEO agency, allows you to turn questions and answers on your …
Schema App Structured Data
schema-app-structured-data-for-schemaorg
Get Schema.org structured data for all pages, posts, categories and profile pages on activation. Use Schema App to customize any Schema Markup.
Boo Recipes Developer Profile
1 plugin · 40 total installs
How We Detect Boo Recipes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/boo-recipes/assets/css/boorecipe.css/wp-content/plugins/boo-recipes/assets/js/boorecipe.js/wp-content/plugins/boo-recipes/assets/js/backend.js/wp-content/plugins/boo-recipes/assets/css/admin.css/wp-content/plugins/boo-recipes/assets/js/boorecipe-admin.jsboo-recipes/assets/css/boorecipe.css?ver=boo-recipes/assets/js/boorecipe.js?ver=boo-recipes/assets/js/backend.js?ver=boo-recipes/assets/css/admin.css?ver=boo-recipes/assets/js/boorecipe-admin.js?ver=HTML / DOM Fingerprints
boorecipe-templateboorecipe-slider-wrapboorecipe-recipe-imageboorecipe-recipe-titleboorecipe-instructionsboorecipe-stepsboorecipe-widgetboorecipe-nutrition-facts+1 more<!-- The code that runs during plugin activation. --><!-- The code that runs during plugin deactivation. --><!-- Begins execution of the plugin. --><!-- exit if file is called directly -->+11 moredata-recipe-iddata-slider-iddata-image-countdata-auto-playdata-intervaldata-navigation+1 morewindow.boorecipevar boorecipe_ajax_object[boorecipe_recipe][boorecipe_slider][boorecipe_nutrition][boorecipe_instructions]