Datalist it Security & Risk Analysis

wordpress.org/plugins/datalistit

Create a table from a csv file to display on a website or blog using Ajax. No technical knowledge required.

10 active installs v0.0.3 PHP + WP 3.0.1+ Updated Unknown
csvdatabaseimporttable
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Datalist it Safe to Use in 2026?

Generally Safe

Score 100/100

Datalist it has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "datalistit" v0.0.3 plugin exhibits several significant security concerns stemming from its static analysis results. A substantial portion of its entry points, specifically all four AJAX handlers, lack authentication checks. This is a critical vulnerability as it allows unauthenticated users to interact with potentially sensitive functionalities. Furthermore, the taint analysis reveals three high-severity flows with unsanitized paths, indicating a strong possibility of code injection or data manipulation vulnerabilities. The low percentage of properly escaped output (13%) and the complete absence of nonce checks further exacerbate these risks, making it easier for attackers to exploit these weaknesses. While the plugin has no recorded vulnerability history, this does not inherently imply security. It may simply be that the plugin hasn't been thoroughly audited or targeted yet. The presence of raw SQL queries and file operations without sufficient security measures in place also contributes to a fragile security posture. In conclusion, "datalistit" v0.0.3 has a poor security posture due to a large unprotected attack surface and critical findings in taint analysis and output handling. Urgent attention is required to address these issues.

Key Concerns

  • Unprotected AJAX handlers
  • High severity taint flows
  • Missing nonce checks
  • Low output escaping percentage
  • Low percentage of prepared SQL statements
  • Missing capability checks
Vulnerabilities
None known

Datalist it Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Datalist it Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
2 prepared
Unescaped Output
7
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
6
External Requests
1
Bundled Libraries
0

SQL Query Safety

20% prepared10 total queries

Output Escaping

13% escaped8 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
dli_backend_css_action_callback (datalistit.php:301)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Datalist it Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

noprivwp_ajax_dli_fronted_actiondatalistit.php:436
authwp_ajax_dli_fronted_actiondatalistit.php:437
authwp_ajax_dli_backend_actiondatalistit.php:440
authwp_ajax_dli_backend_css_actiondatalistit.php:443

Shortcodes 1

[datalistit] datalistit.php:454
WordPress Hooks 4
actionadmin_menudatalistit.php:430
actionadmin_enqueue_scriptsdatalistit.php:433
actionwp_enqueue_scriptsdatalistit.php:451
actionwp_footerdatalistit.php:452
Maintenance & Trust

Datalist it Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Datalist it Developer Profile

datalistit

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Datalist it

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/datalistit/css/datalistit.css/wp-content/plugins/datalistit/js/datalistit.js
Version Parameters
datalistit/style.css?ver=datalistit/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
dlidli_errordli_msgdli_paginatedli_paginate_previousdli_paginate_nextdli_tablefile_name
Data Attributes
id='dli_status'id='dli_message'id='dli_file_upload'id='table_settings'id='dli_advanced'id='dli_css'+3 more
JS Globals
window.dli_tableswindow.dli_id
REST Endpoints
/wp-json/datalistit
Shortcode Output
[datalistit table=[datalistit dbtable=
FAQ

Frequently Asked Questions about Datalist it