Classified Ads Security & Risk Analysis

wordpress.org/plugins/classified-ads

Build your Classified Ads Directory Portal based on Wp Directory Kit and Elementor Plugin

1K active installs v1.0.2 PHP 5.6+ WP 5.2+ Updated Oct 17, 2023
business-directorycars-directoryclassified-adsreal-estate-directory
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Classified Ads Safe to Use in 2026?

Generally Safe

Score 85/100

Classified Ads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "classified-ads" plugin version 1.0.2 demonstrates a strong security posture based on the provided static analysis. The plugin has no recorded vulnerabilities, critical taint flows, or known CVEs, which is a significant positive indicator. The extensive use of capability checks and nonce checks (13 and 5 respectively) suggests a deliberate effort to implement proper authorization and security measures. The lack of file operations and external HTTP requests further reduces the potential attack surface.

However, the analysis reveals a key concern regarding SQL query handling. With one SQL query present and 0% using prepared statements, this represents a significant risk of SQL injection vulnerabilities. Although no specific taint flows were identified in this analysis, this unmitigated SQL query could be a target for attackers. The escaping of output is also only at 70%, meaning that a portion of the plugin's output could be susceptible to cross-site scripting (XSS) attacks, though the severity of these is not detailed.

In conclusion, while the absence of known vulnerabilities and a robust framework of checks are commendable, the unescaped SQL query is a critical flaw that severely undermines the plugin's overall security. The moderate output escaping is also a minor concern. Developers should prioritize addressing the SQL injection risk immediately to prevent potential data breaches or unauthorized access.

Key Concerns

  • SQL queries not using prepared statements
  • Output escaping is not 100%
Vulnerabilities
None known

Classified Ads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Classified Ads Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
37
86 escaped
Nonce Checks
5
Capability Checks
13
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

70% escaped123 total outputs
Attack Surface

Classified Ads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 42
filterwdk/settings/import/multipurpose_valuesextensions\theme-classifield.php:19
filterwdk/settings/import/run/fieldsextensions\theme-classifield.php:20
filterwdk/settings/import/run/postextensions\theme-classifield.php:21
filterwdk/settings/import/run/import_images_dirextensions\theme-classifield.php:22
filterwdk/settings/import/run/import_xml_fileextensions\theme-classifield.php:23
actionwdk/settings/import/runextensions\theme-classifield.php:24
actionwdk/settings/import/api_runextensions\theme-classifield.php:25
filterwdk/settings/import/api_run/import_images_dirextensions\theme-classifield.php:26
filterwdk/settings/import/api_run/import_xml_fileextensions\theme-classifield.php:27
filterwdk/settings/import/run/info_log_messageextensions\theme-classifield.php:28
filterplugin_action_links_classified-ads/classified-ads.phpfilters.php:7
actionplugins_loadedincludes\class-classified-ads.php:146
actionadmin_enqueue_scriptsincludes\class-classified-ads.php:161
actionadmin_enqueue_scriptsincludes\class-classified-ads.php:162
actionadmin_menuincludes\class-classified-ads.php:167
actionwp_enqueue_scriptsincludes\class-classified-ads.php:186
actionwp_enqueue_scriptsincludes\class-classified-ads.php:187
actioninittgm-pa\class-tgm-plugin-activation.php:268
filterload_textdomain_mofiletgm-pa\class-tgm-plugin-activation.php:269
actioninittgm-pa\class-tgm-plugin-activation.php:272
actionadmin_menutgm-pa\class-tgm-plugin-activation.php:421
actionadmin_headtgm-pa\class-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionstgm-pa\class-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionstgm-pa\class-tgm-plugin-activation.php:426
actionadmin_noticestgm-pa\class-tgm-plugin-activation.php:429
actionadmin_inittgm-pa\class-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptstgm-pa\class-tgm-plugin-activation.php:431
actionload-plugins.phptgm-pa\class-tgm-plugin-activation.php:436
actionswitch_themetgm-pa\class-tgm-plugin-activation.php:439
actionswitch_themetgm-pa\class-tgm-plugin-activation.php:442
actionadmin_inittgm-pa\class-tgm-plugin-activation.php:447
actionswitch_themetgm-pa\class-tgm-plugin-activation.php:452
actionload_textdomain_mofiletgm-pa\class-tgm-plugin-activation.php:475
filterupgrader_source_selectiontgm-pa\class-tgm-plugin-activation.php:889
actionplugins_loadedtgm-pa\class-tgm-plugin-activation.php:2116
filtertgmpa_table_data_itemstgm-pa\class-tgm-plugin-activation.php:2240
filterupgrader_source_selectiontgm-pa\class-tgm-plugin-activation.php:2981
actionadmin_inittgm-pa\class-tgm-plugin-activation.php:3151
actionupgrader_process_completetgm-pa\class-tgm-plugin-activation.php:3246
filterupgrader_post_installtgm-pa\class-tgm-plugin-activation.php:3305
filterupgrader_post_installtgm-pa\class-tgm-plugin-activation.php:3450
actiontgmpa_registertgm-pa\configuration.php:36
Maintenance & Trust

Classified Ads Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedOct 17, 2023
PHP min version5.6
Downloads19K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

Classified Ads Developer Profile

WPDirectoryKit

6 plugins · 4K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
101 days
View full developer profile
Detection Fingerprints

How We Detect Classified Ads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/classified-ads/css/classified-ads-admin.css/wp-content/plugins/classified-ads/js/classified-ads-admin.js
Version Parameters
classified-ads-admin?ver=classified-ads?ver=

HTML / DOM Fingerprints

CSS Classes
classified-ads-import-wrap
FAQ

Frequently Asked Questions about Classified Ads