
Business Master Security & Risk Analysis
wordpress.org/plugins/business-masterThe best tool for analysing your website.
Is Business Master Safe to Use in 2026?
Generally Safe
Score 85/100Business Master has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'business-master' plugin version 0.2.0 presents a mixed security posture. On one hand, the static analysis reveals a remarkably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events identified as entry points. Furthermore, the taint analysis shows no identified flows with unsanitized paths, and there's a complete absence of known vulnerabilities in its history, suggesting a generally cautious development approach. However, significant concerns arise from the code signals. The plugin exhibits a very low usage of prepared statements for SQL queries (only 3%), indicating a high risk of SQL injection vulnerabilities, especially given the large number of queries (73). Additionally, a concerning 0% of output is properly escaped, pointing to a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The presence of only one capability check and no nonce checks in the identified entry points further exacerbates these risks, as it suggests that sensitive operations might not be adequately protected against unauthorized access or malicious manipulation.
Key Concerns
- High percentage of SQL queries not using prepared statements
- Zero percent of output properly escaped
- No nonce checks on identified entry points
- Only one capability check found
Business Master Security Vulnerabilities
Business Master Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Business Master Attack Surface
WordPress Hooks 5
Maintenance & Trust
Business Master Maintenance & Trust
Maintenance Signals
Community Trust
Business Master Alternatives
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Site Reviews
site-reviews
Site Reviews is a complete review management solution that integrates with WooCommerce and SureCart and works similarly to reviews on Amazon, Tripadvi …
Reviews and Rating – Google Reviews
g-business-reviews-rating
Completely restriction-free Google reviews and rating as Shortcode/Widget. Extensive display options; delicious themes; includes Structured Data.
Business Master Developer Profile
4 plugins · 220 total installs
How We Detect Business Master
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/business-master/css/mlw_bm_admin.css/wp-content/plugins/business-master/js/mlw_bm_admin.js/wp-content/plugins/business-master/js/mlw_bm_admin.jsbusiness-master/css/mlw_bm_admin.css?ver=business-master/js/mlw_bm_admin.js?ver=HTML / DOM Fingerprints
mlw_bm_email_supportdonation css 0.2.0 Copyright 2014, My Local Webstop (email : fpcorso@mylocalwebstop.com)Generates the support for Business Master+2 morename="emailForm"mlw_bm_validateForm