Business Listing Security & Risk Analysis

wordpress.org/plugins/business-listing

Displays a list of businesses in box with a a description below an image. They can be filter by category and region.

0 active installs v2.2 PHP 5.6+ WP 4.0+ Updated Jan 17, 2026
businessbusiness-directorylistingsshortcodethumbnail
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Business Listing Safe to Use in 2026?

Generally Safe

Score 100/100

Business Listing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "business-listing" plugin v2.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the use of prepared statements for all SQL queries are significant strengths. The plugin also demonstrates good practices with a respectable number of nonce and capability checks relative to its entry points. However, there are areas for improvement. The output escaping is not consistently applied, with 56% properly escaped, leaving potential for cross-site scripting vulnerabilities in the remaining 44% of outputs.

While the taint analysis shows no identified flows, this could be due to the analysis tool's limitations or the plugin's simple structure. The single shortcode represents the only identified entry point, and it is reportedly unprotected, which, though only one instance, could still be a vector if not carefully handled. The external HTTP request, while isolated, warrants attention to ensure it's not vulnerable to certain types of injection attacks. The overall security is good, but the unescaped output and the unprotected shortcode are the primary concerns.

Key Concerns

  • Output escaping not fully implemented
  • Unprotected shortcode entry point
Vulnerabilities
None known

Business Listing Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Business Listing Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
12 prepared
Unescaped Output
27
35 escaped
Nonce Checks
8
Capability Checks
7
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

100% prepared12 total queries

Output Escaping

56% escaped62 total outputs
Attack Surface

Business Listing Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[otg_business_listing] business-listing.php:23
WordPress Hooks 3
actionwp_loadedbusiness-listing.php:24
actionadmin_menubusiness-listing.php:27
actionadmin_enqueue_scriptsbusiness-listing.php:28
Maintenance & Trust

Business Listing Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 17, 2026
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Business Listing Developer Profile

Chris - On the Grid Web Design LLC

3 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Business Listing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/business-listing/business-listing.min.css/wp-content/plugins/business-listing/business-listing.min.js

HTML / DOM Fingerprints

CSS Classes
otgblist_listing_listotgblist_add_listingotgblist_listing_formotgblist_label
HTML Comments
***** Security Check ********** Load Models, Helpers and Libraries ********** Run Bulk Actions if Submitted ********** Get Data *****+3 more
Data Attributes
data-listing-iddata-action
Shortcode Output
<div class="otgblist_listing_list">
FAQ

Frequently Asked Questions about Business Listing