
DevVN Local Store Security & Risk Analysis
wordpress.org/plugins/devvn-local-storeDevVN Local Store help you add stores and search store on google maps.
Is DevVN Local Store Safe to Use in 2026?
Generally Safe
Score 92/100DevVN Local Store has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The devvn-local-store plugin version 1.1.0 presents a mixed security posture. While the absence of known CVEs and no critical taint flows are positive indicators, significant concerns arise from its attack surface and handling of sensitive operations. A notable weakness is the presence of 4 unprotected AJAX handlers, which represent direct entry points for potential attackers. Furthermore, the plugin exhibits poor SQL query hygiene, with 100% of its single SQL query lacking prepared statement usage, increasing the risk of SQL injection vulnerabilities. Although a good percentage of output is properly escaped, the raw SQL and unprotected AJAX handlers remain significant risks.
Considering the vulnerability history, the plugin has a clean slate with no recorded CVEs. This, coupled with the lack of critical taint analysis findings, might suggest a generally well-developed codebase or a lack of exposure to sophisticated attacks. However, the presence of unprotected AJAX handlers and unparameterized SQL queries are fundamental security flaws that do not require complex exploit chains. The plugin's strengths lie in its file operation, external HTTP request handling, and a decent rate of output escaping. However, the identified weaknesses in AJAX security and SQL practices warrant careful consideration, particularly for sites handling sensitive data.
Key Concerns
- Unprotected AJAX handlers
- Raw SQL without prepared statements
- Unescaped output detected
DevVN Local Store Security Vulnerabilities
DevVN Local Store Code Analysis
SQL Query Safety
Output Escaping
DevVN Local Store Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
DevVN Local Store Maintenance & Trust
Maintenance Signals
Community Trust
DevVN Local Store Developer Profile
8 plugins · 44K total installs
How We Detect DevVN Local Store
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/devvn-local-store/assets/css/devvn-localstore.css/wp-content/plugins/devvn-local-store/assets/js/devvn-localstore-jquery.jshttps://maps.googleapis.com/maps/api/jsdevvn-local-store/assets/css/devvn-localstore.css?ver=devvn-local-store/assets/js/devvn-localstore-jquery.js?ver=HTML / DOM Fingerprints
devvn-localstore-wrapperdevvn-localstore-itemdevvn-localstore-item-thumbdevvn-localstore-item-contentdevvn-localstore-item-content-titledevvn-localstore-item-content-addressdevvn-localstore-item-content-phonedevvn-localstore-item-content-email+3 moredata-latdata-lngdata-zoomdata-icondvls_data[devvn_local_stores]