
Cooked – Recipe Management Security & Risk Analysis
wordpress.org/plugins/cookedCooked is the absolute best way to create & display recipes with WordPress. SEO optimized, galleries, timers, and much more.
Is Cooked – Recipe Management Safe to Use in 2026?
Generally Safe
Score 95/100Cooked – Recipe Management has a strong security track record. Known vulnerabilities have been patched promptly.
The "cooked" plugin v1.13.0 presents a mixed security posture. On the positive side, the static analysis shows a robust implementation of security best practices, with all identified entry points (AJAX handlers, REST API routes, shortcodes) appearing to have authorization checks, and a very high percentage of output being properly escaped. The absence of critical or high severity taint flows is also a strong indicator of careful coding regarding input validation.
However, the plugin has a significant history of vulnerabilities, with 11 known medium severity CVEs. While none are currently unpatched, the recurring nature of issues like Cross-site Scripting, Missing Authorization, CSRF, and Improper Encoding suggests potential architectural weaknesses or a history of overlooking certain security nuances. The presence of the `unserialize` function, a known risk vector, even with no identified issues in the taint analysis, warrants careful consideration and ongoing monitoring, especially given the plugin's vulnerability history.
In conclusion, while the current version exhibits good coding practices in terms of input sanitization and output escaping, the extensive vulnerability history necessitates a cautious approach. The plugin's past suggests a tendency for vulnerabilities to emerge, even if not critical, and the use of `unserialize` introduces a latent risk that should be managed.
Key Concerns
- History of 11 medium severity CVEs
- Use of unserialize function
Cooked – Recipe Management Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Cooked <= 1.11.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Cooked <= 1.11.3 - Missing Authorization
Cooked – Recipe Management <= 1.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery to Settings Update
Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery to Template Apply
Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery via cooked_get_recipe_ids
Cooked – Recipe Management <= 1.7.15.4 - Cross-Site Request Forgery to Template Reset
Cooked – Recipe Management <= 1.7.15.4 - Authenticated (Contributor+) HTML Injection
Cooked – Recipe Management <= Authenticated (Contributor+) Stored Cross-Site Scripting
Cooked <= 1.7.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
Cooked <= 1.7.9 - Reflected Cross-Site Scripting
Cooked – Recipe Management Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Cooked – Recipe Management Attack Surface
AJAX Handlers 10
Shortcodes 19
WordPress Hooks 78
Maintenance & Trust
Cooked – Recipe Management Maintenance & Trust
Maintenance Signals
Community Trust
Cooked – Recipe Management Alternatives
WP Recipe Maker
wp-recipe-maker
The easy and user-friendly recipe plugin for everyone. Automatic JSON-LD metadata for food AND how-to recipes will improve your SEO!
Delisho – Recipe Widgets and Blocks
dr-widgets-blocks
Delisho includes 12+ Elementor Widgets and 4 Gutenberg blocks for WP Delicious plugin to create a beautiful and SEO-friendly food blog.
CuratorCrowd Recipe Box
curatorcrowd-recipe-box
An award-winning add-on for your existing recipe cards that enables your visitors to easily save, organize, and share your delicious recipes.
Kulinarian Recipe Embed
kulinarian-recipe-embed
Display recipes on your food blog or cooking related website.
NutritionWP
nutritionwp
Super easy recipe plugin with nutritional facts. Made by a foodie!
Cooked – Recipe Management Developer Profile
1 plugin · 3K total installs
How We Detect Cooked – Recipe Management
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cooked/assets/css/admin.css/wp-content/plugins/cooked/assets/css/style.css/wp-content/plugins/cooked/assets/js/admin.js/wp-content/plugins/cooked/assets/js/frontend.js/wp-content/plugins/cooked/assets/js/admin.js/wp-content/plugins/cooked/assets/js/frontend.jscooked/assets/css/admin.css?ver=cooked/assets/css/style.css?ver=cooked/assets/js/admin.js?ver=cooked/assets/js/frontend.js?ver=HTML / DOM Fingerprints
cooked-recipe-titlecooked-recipe-ingredientscooked-recipe-instructionscooked-recipe-nutritioncooked-recipe-authorcooked-recipe-datecooked-recipe-imagecooked-recipe-meta+2 more<!-- Cooked - Recipe Management -->data-cooked-recipe-iddata-cooked-recipe-titledata-cooked-recipe-permalinkcooked_paramscooked_frontend_params/wp-json/cooked/v1/recipes/wp-json/cooked/v1/recipe/[cooked_recipe[cooked_recipe_archive[cooked_recipe_search