
Five Star Business Profile and Schema Security & Risk Analysis
wordpress.org/plugins/business-profileAdd structured data to any page or post type. Create an SEO friendly contact card with your business info and associated schema.
Is Five Star Business Profile and Schema Safe to Use in 2026?
Generally Safe
Score 100/100Five Star Business Profile and Schema has a strong security track record. Known vulnerabilities have been patched promptly.
The "business-profile" plugin version 2.3.17 demonstrates a generally good security posture, with a strong adherence to secure coding practices like the use of prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of dangerous functions, file operations, and external HTTP requests is also a positive indicator. However, the presence of one AJAX handler lacking authentication checks introduces a significant risk of unauthorized actions if an attacker can trigger this handler.
The static analysis did not reveal any critical or high-severity taint flows, which is reassuring. The plugin's vulnerability history shows one medium-severity CVE related to Cross-site Scripting, which was last documented in early 2022 and is reported as currently unpatched. While the immediate static analysis doesn't flag XSS, the historical context warrants caution, especially concerning the unprotected AJAX endpoint.
In conclusion, the plugin exhibits strengths in fundamental security practices. The primary concern stems from the unprotected AJAX handler, which can serve as an entry point for unauthorized operations. The historical medium-severity XSS vulnerability, although not actively present in the current code analysis, suggests a potential for input sanitization issues that should be carefully monitored. Addressing the unprotected AJAX handler is the most pressing security recommendation.
Key Concerns
- AJAX handler without authentication checks
- Medium severity CVE history
Five Star Business Profile and Schema Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Five Star Business Profile and Schema <= 2.1.6 - Subscriber+ Page Creation & Settings Update to Stored Cross-Site Scripting
Five Star Business Profile and Schema Code Analysis
Output Escaping
Data Flow Analysis
Five Star Business Profile and Schema Attack Surface
AJAX Handlers 9
Shortcodes 1
WordPress Hooks 51
Maintenance & Trust
Five Star Business Profile and Schema Maintenance & Trust
Maintenance Signals
Community Trust
Five Star Business Profile and Schema Alternatives
Post to Google My Business (Google Business Profile)
post-to-google-my-business
Auto-publish posts, pages & CPTs, plus manage Google Business Profile posts. All from your WordPress dashboard!
Local Business Schema (JSON-LD) Lite
wpspeed-localbusiness-schema
Boost Local SEO with Smart Local Business Schema JSON-LD
Local Business Schema Generator
local-business-schema-generator
Add Google-friendly LocalBusiness and WebSite schema to your WordPress site—no coding required.
Local SEO By Ankit Rawat
local-seo-by-ankit-rawat
Boost Local Search Rankings with the ultimate Local SEO plugin. Add schema, integrate Google My Business, and attract more local customers easily.
hCard Widget for WordPress
hcard-widget
Creates a widget that outputs contact information for individuals or organizations with Schema.org compliant markup.
Five Star Business Profile and Schema Developer Profile
21 plugins · 66K total installs
How We Detect Five Star Business Profile and Schema
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/business-profile/assets/css/contact-card.css/wp-content/plugins/business-profile/assets/js/map.js/wp-content/plugins/business-profile/assets/js/map.jsbusiness-profile/assets/css/contact-card.css?ver=business-profile/assets/js/map.js?ver=