Directorykit Car Dealer Addon Security & Risk Analysis

wordpress.org/plugins/directorykit-car-dealer-addon

Transforms WordPress into a car dealership portal with demo listings; fully customizable with Elementor for automotive sites.

0 active installs v1.0.0 PHP 7.0+ WP 5.2+ Updated Mar 10, 2026
automotive-directorycar-dealershipdirecade-directorydirectory
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Directorykit Car Dealer Addon Safe to Use in 2026?

Generally Safe

Score 100/100

Directorykit Car Dealer Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 24d ago
Risk Assessment

This plugin exhibits a concerning security posture primarily due to its unprotected entry points. All four identified AJAX handlers lack authentication checks, meaning any authenticated WordPress user could potentially trigger these functions. While the static analysis did not reveal any critical or high-severity vulnerabilities like unsanitized taint flows or dangerous functions, the lack of proper authorization on AJAX actions presents a significant risk of privilege escalation or unauthorized operations if these handlers perform sensitive tasks. The fact that the plugin has no recorded vulnerability history is a positive sign, suggesting a good track record or limited exposure to security scrutiny so far. However, this does not negate the immediate risks posed by the unprotected AJAX endpoints. The plugin shows some good practices like a nonce check and capability checks on some points, and the output escaping is moderately good. The primary weakness lies in securing the attack surface, which needs immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • SQL queries without prepared statements
  • Moderate output escaping efficiency
Vulnerabilities
None known

Directorykit Car Dealer Addon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Directorykit Car Dealer Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
30
50 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

63% escaped80 total outputs
Attack Surface
4 unprotected

Directorykit Car Dealer Addon Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_direcade_activate_pluginactions.php:7
authwp_ajax_direcade_admin_actionincludes\class-directorykit-car-dealer-addon.php:165
authwp_ajax_direcade_public_actionincludes\class-directorykit-car-dealer-addon.php:188
noprivwp_ajax_direcade_public_actionincludes\class-directorykit-car-dealer-addon.php:194
WordPress Hooks 29
filterupload_mimesactions.php:37
actionwp_enqueue_scriptselementor-elements\elementor-init.php:221
actionwp_enqueue_scriptselementor-elements\elementor-init.php:222
actionelementor/elements/categories_registeredelementor-elements\elementor-init.php:224
actionelementor/widgets/registerelementor-elements\elementor-init.php:225
actionelementor/initelementor-elements\elementor-init.php:238
filterwdk/settings/import/multipurpose_valuesextensions\theme-carkit.php:19
filterwdk/settings/import/run/fieldsextensions\theme-carkit.php:20
filterwdk/settings/import/run/postextensions\theme-carkit.php:21
filterwdk/settings/import/run/import_images_dirextensions\theme-carkit.php:22
filterwdk/settings/import/run/import_xml_fileextensions\theme-carkit.php:23
filterwdk/settings/import/run/import_xml_file_locationsextensions\theme-carkit.php:24
actionwdk/settings/import/runextensions\theme-carkit.php:25
actionwdk/settings/import/api_runextensions\theme-carkit.php:26
filterwdk/settings/import/api_run/import_images_dirextensions\theme-carkit.php:27
filterwdk/settings/import/api_run/import_xml_fileextensions\theme-carkit.php:28
filterwdk/settings/import/api_run/import_xml_file_locationsextensions\theme-carkit.php:29
filterwdk/settings/import/run/info_log_messageextensions\theme-carkit.php:30
actionwpdirectorykit/elementor-elements/register_widgetextensions\theme-carkit.php:94
actionwpdirectorykit/elementor-elements/register_widgetextensions\theme-carkit.php:118
filterplugin_action_links_directorykit-car-dealer-addon/directorykit-car-dealer-addon.phpfilters.php:7
actionadmin_enqueue_scriptsincludes\class-directorykit-car-dealer-addon.php:153
actionadmin_enqueue_scriptsincludes\class-directorykit-car-dealer-addon.php:154
actionadmin_menuincludes\class-directorykit-car-dealer-addon.php:159
actionwp_enqueue_scriptsincludes\class-directorykit-car-dealer-addon.php:184
actionwp_enqueue_scriptsincludes\class-directorykit-car-dealer-addon.php:185
actionplugins_loadedincludes\class-directorykit-car-dealer-addon.php:245
filterajax_query_attachments_argsincludes\class-directorykit-car-dealer-addon.php:263
actionadmin_enqueue_scriptsviews\import-page.php:167
Maintenance & Trust

Directorykit Car Dealer Addon Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 10, 2026
PHP min version7.0
Downloads138

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Directorykit Car Dealer Addon Developer Profile

WPDirectoryKit

6 plugins · 4K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
101 days
View full developer profile
Detection Fingerprints

How We Detect Directorykit Car Dealer Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/directorykit-car-dealer-addon/admin/css/directorykit-car-dealer-addon-admin.css/wp-content/plugins/directorykit-car-dealer-addon/admin/css/directorykit-car-dealer-addon-admin-responsive.css/wp-content/plugins/directorykit-car-dealer-addon/admin/js/directorykit-car-dealer-addon-admin.js/wp-content/plugins/directorykit-car-dealer-addon/admin/js/install.js
Script Paths
/wp-content/plugins/directorykit-car-dealer-addon/admin/js/directorykit-car-dealer-addon-admin.js/wp-content/plugins/directorykit-car-dealer-addon/admin/js/install.js
Version Parameters
directorykit-car-dealer-addon/admin/css/directorykit-car-dealer-addon-admin.css?ver=directorykit-car-dealer-addon/admin/css/directorykit-car-dealer-addon-admin-responsive.css?ver=directorykit-car-dealer-addon/admin/js/directorykit-car-dealer-addon-admin.js?ver=directorykit-car-dealer-addon/admin/js/install.js?ver=

HTML / DOM Fingerprints

JS Globals
direcade_script_parametersdirecade_importer_params
FAQ

Frequently Asked Questions about Directorykit Car Dealer Addon