Cocktail Recipes Security & Risk Analysis

wordpress.org/plugins/cocktail-recipes

Elegant, structured cocktail recipe rendering using a simple shortcode, with automatic formatting and unit conversion.

0 active installs v1.1.0 PHP 7.4+ WP 5.8+ Updated Jan 18, 2026
cocktailsdrinkmixologyrecipesshortcode
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cocktail Recipes Safe to Use in 2026?

Generally Safe

Score 100/100

Cocktail Recipes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The cocktail-recipes plugin version 1.1.0 exhibits a generally strong security posture based on the static analysis provided. It demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping a very high percentage of its output. The absence of known vulnerabilities and a clean vulnerability history further contribute to a positive security outlook. Furthermore, the plugin has a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed. The presence of nonce and capability checks, though few, also indicates some level of security awareness in its development.

However, a significant concern arises from the presence of the `unserialize` function. This function is notoriously dangerous if used with untrusted user input, as it can lead to remote code execution vulnerabilities. While the static analysis doesn't explicitly show a direct taint flow to `unserialize`, its mere presence without further context or sanitization mechanisms warrants careful consideration. The analysis also indicates a lack of file operations being checked for security implications, which, combined with the `unserialize` function, could be a point of exploitation if user-supplied data influences file handling or serialization.

In conclusion, the cocktail-recipes plugin has many strengths, including a minimal attack surface and secure SQL handling. The absence of past vulnerabilities is a significant positive indicator. Nevertheless, the identified `unserialize` function represents a critical potential risk that cannot be overlooked. Without more detailed taint analysis specifically around this function, or evidence of strict input validation preceding its use, this plugin carries a moderate risk. Future versions should aim to eliminate the use of `unserialize` or implement robust input sanitization.

Key Concerns

  • Dangerous function unserialize found
Vulnerabilities
None known

Cocktail Recipes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Cocktail Recipes Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
5
179 escaped
Nonce Checks
1
Capability Checks
6
File Operations
8
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserializeif ($cacheData && ($recipe = @unserialize($cacheData)) instanceof Recipe) {includes\Shortcodes\CocktailShortcode.php:148

Output Escaping

97% escaped184 total outputs
Attack Surface

Cocktail Recipes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionupgrader_process_completeincludes\Core\Base\Plugin.php:465
actioninitincludes\Core\Base\Plugin.php:482
actionadmin_initincludes\Core\Base\Plugin.php:486
filtercron_schedulesincludes\Core\Base\Plugin.php:499
actionwp_enqueue_scriptsincludes\Core\Base\Plugin.php:503
actionadmin_enqueue_scriptsincludes\Core\Base\Plugin.php:522
actionadmin_menuincludes\Core\Base\Plugin.php:543
actionadmin_noticesincludes\Core\Base\Plugin.php:547
filterplugin_row_metaincludes\Core\Base\Plugin.php:597
filterthe_contentincludes\Core\Base\Shortcode.php:160
Maintenance & Trust

Cocktail Recipes Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 18, 2026
PHP min version7.4
Downloads166

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Cocktail Recipes Developer Profile

Ian S Goldstein

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cocktail Recipes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cocktail-recipes/asset/css/cocktail-recipes.css/wp-content/plugins/cocktail-recipes/asset/js/cocktail-recipes.js/wp-content/plugins/cocktail-recipes/asset/js/cocktail-recipes.js?ver=1.1.0
Script Paths
/wp-content/plugins/cocktail-recipes/asset/js/cocktail-recipes.js
Version Parameters
cocktail-recipes/asset/css/cocktail-recipes.css?ver=cocktail-recipes/asset/js/cocktail-recipes.js?ver=

HTML / DOM Fingerprints

CSS Classes
cocktail-recipescocktail-recipes-containercocktail-recipes-titlecocktail-recipes-instructionscocktail-recipes-ingredientscocktail-recipes-garnish
HTML Comments
<!-- Generated by Cocktail Recipes plugin -->
Data Attributes
data-cocktail-recipes-id
JS Globals
cocktail_recipes_ajax_object
Shortcode Output
[cocktail-recipes][cocktail-recipes id=
FAQ

Frequently Asked Questions about Cocktail Recipes