Dokan Plus Security & Risk Analysis

wordpress.org/plugins/dokan-plus

This plugin will help you to restrict your marketplace built with Dokan Multivendor Marketplace.

20 active installs v1.0.4 PHP 5.6+ WP 4.4+ Updated Unknown
dokandokan-litemulti-vendormultishopmultivendor-marketplace
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dokan Plus Safe to Use in 2026?

Generally Safe

Score 100/100

Dokan Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the provided static analysis and vulnerability history, Dokan-Plus v1.0.4 exhibits a strong security posture. The absence of any identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events significantly reduces the plugin's attack surface. Furthermore, the code analysis indicates robust security practices with no dangerous functions, 100% utilization of prepared statements for SQL queries, and complete output escaping. The lack of file operations, external HTTP requests, and the absence of untainted taint flows further bolster its security profile. The plugin also has no recorded vulnerability history, which is a positive indicator of its stability and secure development. The primary area of potential concern, although not explicitly stated as a weakness in this data, is the complete lack of explicit capability and nonce checks. While the static analysis shows zero entry points, which by definition wouldn't require these checks, it's worth noting that future updates introducing such entry points would necessitate their implementation to maintain this high security standard. In conclusion, Dokan-Plus v1.0.4 appears to be a very secure plugin based on the provided data, with no immediate exploitable vulnerabilities or significant code-level risks identified.

Vulnerabilities
None known

Dokan Plus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Dokan Plus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Dokan Plus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_noticesdokan-plus.php:40
actionadmin_noticesdokan-plus.php:54
filterdokan_settings_fieldsdokan-plus.php:146
actiondokan_seller_listing_after_featureddokan-plus.php:147
actiondokan_store_header_info_fieldsdokan-plus.php:148
actiondokan_loadeddokan-plus.php:151
Maintenance & Trust

Dokan Plus Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedUnknown
PHP min version5.6
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Dokan Plus Developer Profile

cscode

2 plugins · 120 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dokan Plus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
dvih-notice-dismissedstore-phonedokan-store-phonestore-emaildokan-store-emailstore-addressdokan-store-addressstreet_1+5 more
FAQ

Frequently Asked Questions about Dokan Plus