Dadevarzan WordPress Common Security & Risk Analysis

wordpress.org/plugins/dadevarzan-common

Dadevarzan Common Plugin

700 active installs v2.2.3 PHP 7.4+ WP 4.4.0+ Updated Aug 25, 2025
commondadehvarzandadevarzanwordpresswp
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 3, 2025
Safety Verdict

Is Dadevarzan WordPress Common Safe to Use in 2026?

Generally Safe

Score 99/100

Dadevarzan WordPress Common has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 3, 2025Updated 7mo ago
Risk Assessment

The 'dadevarzan-common' plugin version 2.2.3 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query sanitation and output escaping, with 100% of both being properly handled. The absence of dangerous functions, external HTTP requests, and bundled libraries is also a strength. However, significant concerns arise from the attack surface, particularly the presence of one AJAX handler without authentication checks. This creates an unprotected entry point that could be exploited by an attacker to trigger unintended actions or gather information.

The vulnerability history reveals a past medium-severity Cross-Site Scripting (XSS) vulnerability, which, while currently patched, indicates a potential for such issues to arise. The lack of nonce checks and capability checks further exacerbates the risk associated with the unprotected AJAX handler, as there are no built-in mechanisms to verify the legitimacy of requests or the user's permissions. While the static analysis did not reveal critical or high severity taint flows in this specific version, the combination of an exposed AJAX endpoint and historical vulnerability patterns warrants careful consideration.

In conclusion, while the plugin has made strides in secure coding practices for SQL and output handling, the unprotected AJAX entry point and the historical XSS vulnerability represent notable weaknesses. The absence of comprehensive authorization checks on all entry points, especially the identified AJAX handler, is the most pressing security concern. This version is not critically vulnerable in its current static analysis, but the potential for exploitation exists due to the exposed functionality.

Key Concerns

  • Unprotected AJAX handler
  • No nonce checks
  • No capability checks
  • Medium severity vulnerability history
Vulnerabilities
1

Dadevarzan WordPress Common Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58632medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dadevarzan WordPress Common <= 2.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 3, 2025 Patched in 2.2.3 (7d)
Code Analysis
Analyzed Mar 16, 2026

Dadevarzan WordPress Common Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
58 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped58 total outputs
Attack Surface
1 unprotected

Dadevarzan WordPress Common Attack Surface

Entry Points18
Unprotected1

AJAX Handlers 1

authwp_ajax_dv_reload_iconsincludes\class-dadevarzan-iconfonts.php:26

Shortcodes 17

[acf-if] includes\class-acf.php:13
[acf-loop] includes\class-acf.php:14
[acf-nested-loop] includes\class-acf.php:15
[acf-file] includes\class-acf.php:16
[acf-if] includes\class-asf-shortcode.php:7
[acf-loop] includes\class-asf-shortcode.php:8
[dv-powered-by] includes\class-dadevarzan-shortcode.php:6
[dv-powered-by] includes\class-dadevarzan.php:13
[dv-child-pages] includes\class-dadevarzan.php:14
[dv-tax] includes\class-dadevarzan.php:15
[dv-all-tax] includes\class-dadevarzan.php:16
[blog] includes\class-dadevarzan.php:17
[dv-date-filter] includes\class-dadevarzan.php:18
[dv-jdate] includes\class-date-shortcode.php:7
[user-if] includes\class-user.php:13
[user-info] includes\class-user.php:14
[display_attribute] includes\class-WooCommerce.php:12
WordPress Hooks 23
actionplugins_loadeddadevarzan-common.php:82
actionacf/initincludes\class-acf.php:19
filteruser_has_capincludes\class-capability-management.php:13
actionadmin_headincludes\class-capability-management.php:14
actionadmin_headincludes\class-capability-management.php:15
actionadmin_bar_menuincludes\class-capability-management.php:16
filteruser_has_capincludes\class-capability-management.php:64
actionwp_headincludes\class-dadevarzan.php:20
actionpre_get_postsincludes\class-dadevarzan.php:21
filterfl_builder_column_custom_classincludes\class-dadevarzan.php:23
filterfl_builder_module_custom_classincludes\class-dadevarzan.php:24
actioninitincludes\class-fl-font.php:6
actionwp_enqueue_scriptsincludes\class-fl-font.php:7
filterwalker_nav_menu_start_elincludes\class-fl-mega-menu.php:12
filterwp_nav_menuincludes\class-fl-mega-menu.php:14
filterfl_theme_system_fontsincludes\class-font.php:13
filterfl_builder_font_families_systemincludes\class-font.php:14
actionwp_enqueue_scriptsincludes\class-font.php:16
actionadmin_enqueue_scriptsincludes\class-font.php:17
actionadmin_initincludes\class-gravity.php:15
actionpre_get_postsincludes\class-WooCommerce.php:11
actioninitincludes\class-WooCommerce.php:13
actioninitincludes\class-WooCommerce.php:14
Maintenance & Trust

Dadevarzan WordPress Common Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 25, 2025
PHP min version7.4
Downloads17K

Community Trust

Rating0/100
Number of ratings0
Active installs700
Developer Profile

Dadevarzan WordPress Common Developer Profile

Dadevarzan

19 plugins · 2K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Dadevarzan WordPress Common

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dadevarzan-common/public/css/IRANSansWeb.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Dadevarzan WordPress Common