
Dadevarzan WordPress Book Security & Risk Analysis
wordpress.org/plugins/dadevarzan-wp-bookDadevarzan Book Post Type
Is Dadevarzan WordPress Book Safe to Use in 2026?
Generally Safe
Score 85/100Dadevarzan WordPress Book has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The dadevarzan-wp-book v1.2.4 plugin exhibits a generally strong security posture based on the provided static analysis. All identified entry points (shortcodes) appear to be free of direct vulnerabilities in terms of dangerous functions, SQL injection (all queries use prepared statements), and output escaping. The absence of file operations, external HTTP requests, and taint analysis findings further reinforces this positive assessment. The plugin also has a clean vulnerability history with no known CVEs, indicating a lack of publicly disclosed security flaws.
However, a significant concern arises from the complete lack of nonce checks and capability checks. While the static analysis did not reveal immediate exploitable flaws within the current code, the absence of these fundamental WordPress security mechanisms means that any functionality exposed by the shortcodes is effectively unprotected from unauthorized access or manipulation by unauthenticated users. This creates a potential avenue for Cross-Site Request Forgery (CSRF) attacks or other privilege escalation vectors if the shortcode's functionality were to be exploited in conjunction with other vulnerabilities or by manipulating requests. The plugin's attack surface, though small, is entirely unprotected in this regard, which is a critical oversight.
In conclusion, while the code itself seems well-written with good practices like prepared statements and proper output escaping, the omission of nonce and capability checks is a glaring security weakness. The plugin is functionally secure in terms of known vulnerabilities and code-level data handling, but its overall security is compromised by the lack of authorization and CSRF protection mechanisms for its shortcode-based functionality.
Key Concerns
- Missing nonce checks
- Missing capability checks
Dadevarzan WordPress Book Security Vulnerabilities
Dadevarzan WordPress Book Code Analysis
Output Escaping
Dadevarzan WordPress Book Attack Surface
Shortcodes 2
WordPress Hooks 7
Maintenance & Trust
Dadevarzan WordPress Book Maintenance & Trust
Maintenance Signals
Community Trust
Dadevarzan WordPress Book Alternatives
Dadevarzan WordPress Common
dadevarzan-common
Dadevarzan Common Plugin
Dadevarzan Common for Woocommerce
dadevarzan-woo-common
Dadevarzan custom shortcodes and common functionalites for Woocommerce.
Dadevarzan WordPress Gallery
dadevarzan-wp-gallery
Dadevarzan Gallery Post Type
Dadevarzan WordPress Tender
dadevarzan-wp-tender
Dadevarzan Tender Post Type
Dadevarzan WordPress Video
dadevarzan-wp-video
Dadevarzan Video Post Type
Dadevarzan WordPress Book Developer Profile
19 plugins · 2K total installs
How We Detect Dadevarzan WordPress Book
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dadevarzan-wp-book/assets/style.css/wp-content/plugins/dadevarzan-wp-book/assets/script.js/wp-content/plugins/dadevarzan-wp-book/assets/script.jsdadevarzan-wp-book/assets/style.css?ver=dadevarzan-wp-book/assets/script.js?ver=HTML / DOM Fingerprints
dv-book-filter-wrapdata-dv-book-filterdadevarzan_wp_book_filter<div class="dv-book-filter-wrap" data-dv-book-filter='{</div><table class="dv-book-table"><th scope="col">