
Dadevarzan WordPress Common Security & Risk Analysis
wordpress.org/plugins/dadevarzan-commonDadevarzan Common Plugin
Is Dadevarzan WordPress Common Safe to Use in 2026?
Generally Safe
Score 99/100Dadevarzan WordPress Common has a strong security track record. Known vulnerabilities have been patched promptly.
The 'dadevarzan-common' plugin version 2.2.3 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query sanitation and output escaping, with 100% of both being properly handled. The absence of dangerous functions, external HTTP requests, and bundled libraries is also a strength. However, significant concerns arise from the attack surface, particularly the presence of one AJAX handler without authentication checks. This creates an unprotected entry point that could be exploited by an attacker to trigger unintended actions or gather information.
The vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, which, while currently patched, indicates a potential for such issues to arise. The lack of nonce checks and capability checks further exacerbates the risk associated with the unprotected AJAX handler, as there are no built-in mechanisms to verify the legitimacy of requests or the user's permissions. While the static analysis did not reveal critical or high severity taint flows in this specific version, the combination of an exposed AJAX endpoint and historical vulnerability patterns warrants careful consideration.
In conclusion, while the plugin has made strides in secure coding practices for SQL and output handling, the unprotected AJAX entry point and the historical XSS vulnerability represent notable weaknesses. The absence of comprehensive authorization checks on all entry points, especially the identified AJAX handler, is the most pressing security concern. This version is not critically vulnerable in its current static analysis, but the potential for exploitation exists due to the exposed functionality.
Key Concerns
- Unprotected AJAX handler
- No nonce checks
- No capability checks
- Medium severity vulnerability history
Dadevarzan WordPress Common Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Dadevarzan WordPress Common <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Dadevarzan WordPress Common Code Analysis
Output Escaping
Dadevarzan WordPress Common Attack Surface
AJAX Handlers 1
Shortcodes 17
WordPress Hooks 23
Maintenance & Trust
Dadevarzan WordPress Common Maintenance & Trust
Maintenance Signals
Community Trust
Dadevarzan WordPress Common Alternatives
Dadevarzan Common for Woocommerce
dadevarzan-woo-common
Dadevarzan custom shortcodes and common functionalites for Woocommerce.
Dadevarzan WordPress Gallery
dadevarzan-wp-gallery
Dadevarzan Gallery Post Type
Dadevarzan WordPress Tender
dadevarzan-wp-tender
Dadevarzan Tender Post Type
Dadevarzan WordPress Video
dadevarzan-wp-video
Dadevarzan Video Post Type
Dadevarzan WordPress Personnel
dadevarzan-wp-personnel
Dadevarzan Personnel Post Type
Dadevarzan WordPress Common Developer Profile
19 plugins · 2K total installs
How We Detect Dadevarzan WordPress Common
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dadevarzan-common/public/css/IRANSansWeb.css