
DD – Business Card Widget Security & Risk Analysis
wordpress.org/plugins/dd-business-card-widgetA semantic business information widget for wordpress. Sections for business name, address, contact, opening hours and additional information.
Is DD – Business Card Widget Safe to Use in 2026?
Generally Safe
Score 85/100DD – Business Card Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "dd-business-card-widget" plugin v1.4.2 reveals a generally positive security posture, with a notably clean attack surface and no identified critical vulnerabilities in code signals or taint analysis. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and file operations significantly reduces the potential for external exploitation. Furthermore, the plugin demonstrates good practices in its handling of SQL queries, with 100% using prepared statements, and no dangerous functions were detected.
However, a significant concern arises from the output escaping, where 100% of detected outputs are not properly escaped. This means that any data displayed by the widget, if it originates from user input or external sources, could be vulnerable to Cross-Site Scripting (XSS) attacks. The lack of nonce and capability checks on any potential entry points (though none were found in this specific analysis) is also a missed opportunity for robust authorization and validation, especially if the plugin were to evolve or have hidden entry points not captured by the current analysis.
The vulnerability history being completely clear of CVEs is a strong indicator of past diligence or perhaps a lack of focused security auditing. While this is positive, the current findings regarding unescaped output highlight that even without past vulnerabilities, ongoing security vigilance and adherence to best practices in all code areas, including output handling, are crucial for maintaining a secure plugin.
Key Concerns
- Unescaped output detected
- No nonce checks found
- No capability checks found
DD – Business Card Widget Security Vulnerabilities
DD – Business Card Widget Code Analysis
Output Escaping
DD – Business Card Widget Attack Surface
WordPress Hooks 3
Maintenance & Trust
DD – Business Card Widget Maintenance & Trust
Maintenance Signals
Community Trust
DD – Business Card Widget Alternatives
Smart Contact Card
smart-contact-card
Shareable contact cards with QR codes and vCard via shortcode, Gutenberg block, and Elementor widget.
Business Card Template
business-card-template
Business Card Template
HelloBox
hellobox
Responsive, highly visible contact call-to-action. Combining instant-contact buttons, vCard import, location, business hours, messaging and more.
QR code MeCard/vCard generator
wp-qrcode-me-v-card
Share your contact information such as emails, phone number and much more through QR code with WordPress using shortcode, widget or by direct link.
CT Contact
ct-contact
Want to display your personal or business contact information? Then this awesome lil' contact widget plugin is for you.
DD – Business Card Widget Developer Profile
2 plugins · 50 total installs
How We Detect DD – Business Card Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dd-business-card-widget/styles/admin.css/wp-content/plugins/dd-business-card-widget/scripts/admin.js/wp-content/plugins/dd-business-card-widget/scripts/admin.js