Connections Business Directory Education Level Security & Risk Analysis

wordpress.org/plugins/connections-business-directory-education-levels

Extension for the Connections Business Directory that adds the ability to add an education level to an entry.

50 active installs v3.0.2 PHP 7.0+ WP 5.6+ Updated Apr 13, 2024
address-bookaddressbookaddressesbiobios
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Connections Business Directory Education Level Safe to Use in 2026?

Generally Safe

Score 92/100

Connections Business Directory Education Level has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of "connections-business-directory-education-levels" v3.0.2 reveals a generally strong security posture. The plugin demonstrates good practices by having zero AJAX handlers, REST API routes, shortcodes, or cron events without authentication or permission checks. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. All identified SQL queries are correctly prepared, and there are no recorded vulnerabilities in its history.

However, there are areas for improvement. With 50% of outputs being unescaped, there's a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without proper sanitization. The lack of any identified taint flows, while seemingly positive, might indicate that the taint analysis engine couldn't effectively analyze the code, or that the plugin's functionality is very limited. Similarly, the absence of nonce checks and capability checks, while currently not a revealed vulnerability, represents a potential weakness if new entry points are introduced in the future.

In conclusion, the plugin shows a solid foundation with no immediately apparent critical or high-severity flaws. The focus on prepared statements and a clean vulnerability history are significant strengths. The primary concern is the unescaped output, which requires immediate attention to prevent potential XSS attacks. The lack of broader checks for nonces and capabilities warrants a review to ensure future extensibility remains secure.

Key Concerns

  • Unescaped output detected
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Connections Business Directory Education Level Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Connections Business Directory Education Level Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped6 total outputs
Attack Surface

Connections Business Directory Education Level Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioncn_metaboxconnections_education_levels.php:165
filtercn_csv_export_fields_configconnections_education_levels.php:168
filtercn_export_header-education_levelconnections_education_levels.php:169
filtercn_export_field-education_levelconnections_education_levels.php:170
filtercncsv_map_import_fieldsconnections_education_levels.php:173
actioncncsv_import_fieldsconnections_education_levels.php:174
filtercn_content_blocksconnections_education_levels.php:185
actionwidgets_initconnections_education_levels.php:191
actionadmin_noticesconnections_education_levels.php:489
actionplugins_loadedconnections_education_levels.php:504
Maintenance & Trust

Connections Business Directory Education Level Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 13, 2024
PHP min version7.0
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

Connections Business Directory Education Level Developer Profile

Steven

14 plugins · 1K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Connections Business Directory Education Level

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/connections-business-directory-education-levels/includes/class.widgets.php/wp-content/plugins/connections-business-directory-education-levels/includes/Content_Blocks/Education_Level.php
Version Parameters
connections-business-directory-education-levels/includes/class.widgets.php?ver=connections-business-directory-education-levels/includes/Content_Blocks/Education_Level.php?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- This should run on the `plugins_loaded` action hook. Since the extension loads on the * `plugins_loaded` action hook, load immediately. --><!-- * Register the content block. * * Call `\Connections_Directory\Content_Blocks::instance()->renderBlock( 'education_level', $entry );` to render in a template. --><!-- Add the action that'll be run when calling $entry->getContentBlock( 'education_level' ) from within a template. -->
Data Attributes
data-cn-education_level
JS Globals
Connections_Education_Levels
REST Endpoints
/wp-json/connections-education-levels
Shortcode Output
[connections_education_levels]
FAQ

Frequently Asked Questions about Connections Business Directory Education Level