E-namad & Shamed Logo Manager Security & Risk Analysis

wordpress.org/plugins/e-namad-shamed-logo-manager

This plugin helps you to easily put the logo of E-namad, Shamed and Zarrinpal on your website

3K active installs v2.2 PHP 7.0+ WP 4.7+ Updated Aug 20, 2020
enamadenamad-logoresaneh-logoshamed-logo
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is E-namad & Shamed Logo Manager Safe to Use in 2026?

Use With Caution

Score 63/100

E-namad & Shamed Logo Manager has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 5yr ago
Risk Assessment

The e-namad-shamed-logo-manager plugin v2.2 exhibits a mixed security posture. While the static analysis shows positive signs like 100% of SQL queries using prepared statements and no detected dangerous functions or file operations, there are significant concerns. The plugin has a known medium severity Cross-Site Scripting (XSS) vulnerability that is currently unpatched, indicating a potential for attackers to inject malicious scripts into the application. Furthermore, the absence of nonce checks and capability checks across its entry points is a critical weakness, as it allows unauthorized users to trigger actions or access data that should be protected. The 65% proper output escaping suggests that some content displayed to users might be vulnerable to XSS attacks if not handled carefully by the remaining 35% of outputs.

The vulnerability history clearly points to a recurring issue with XSS vulnerabilities, and the presence of an unpatched medium severity CVE is a direct and immediate risk. The static analysis, while highlighting some good practices in database interaction, fails to identify any taint flows, which might be due to the analysis scope or a lack of complex data handling. However, the lack of authorization checks on all entry points (shortcodes in this case) is a glaring omission that attackers can readily exploit. The total attack surface is small, but the lack of security on these entry points negates this advantage.

In conclusion, despite some positive coding practices in handling SQL and avoiding dangerous functions, the e-namad-shamed-logo-manager plugin v2.2 poses a significant risk due to an unpatched XSS vulnerability and a complete lack of authorization checks on its shortcodes. The history of XSS vulnerabilities further exacerbates this risk, suggesting a potential for ongoing security issues. Immediate patching of the known CVE and implementation of proper authorization and nonce checks on all entry points are strongly recommended.

Key Concerns

  • Unpatched medium severity CVE
  • Lack of nonce checks on entry points
  • Lack of capability checks on entry points
  • Insufficient output escaping (35%)
Vulnerabilities
1

E-namad & Shamed Logo Manager Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-57998medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

E-namad &amp; Shamed Logo Manager <= 2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

E-namad & Shamed Logo Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
26 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

65% escaped40 total outputs
Attack Surface

E-namad & Shamed Logo Manager Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[enamadlogo_shortcode] index.php:44
[shamedlogo_shortcode] index.php:45
[zarrinpallogo_shortcode] index.php:46
[ywp_esl_logos] index.php:47
WordPress Hooks 7
actionadmin_menuindex.php:35
actionadmin_initindex.php:38
filterwp_targeted_link_relindex.php:50
actionwidgets_initwidget\class-widget-all.php:2
actionwidgets_initwidget\class-widget-enamad.php:2
actionwidgets_initwidget\class-widget-shamed.php:2
actionwidgets_initwidget\class-widget-zarrin.php:2
Maintenance & Trust

E-namad & Shamed Logo Manager Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 20, 2020
PHP min version7.0
Downloads26K

Community Trust

Rating88/100
Number of ratings7
Active installs3K
Developer Profile

E-namad & Shamed Logo Manager Developer Profile

Hamid Reza Yazdani

2 plugins · 3K total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect E-namad & Shamed Logo Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/e-namad-shamed-logo-manager/widget/class-widget-all.php/wp-content/plugins/e-namad-shamed-logo-manager/widget/class-widget-enamad.php/wp-content/plugins/e-namad-shamed-logo-manager/widget/class-widget-shamed.php/wp-content/plugins/e-namad-shamed-logo-manager/widget/class-widget-zarrin.php/wp-content/plugins/e-namad-shamed-logo-manager/templates/option-page.php
Version Parameters
e-namad-shamed-logo-manager/style.css?ver=e-namad-shamed-logo-manager/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
ywp-esl-logo-container
Data Attributes
data-enamad-logodata-shamed-logodata-zarrinpal-logo
JS Globals
window.ywp_esl_logos_data
Shortcode Output
[enamadlogo_shortcode][shamedlogo_shortcode][zarrinpallogo_shortcode][ywp_esl_logos]
FAQ

Frequently Asked Questions about E-namad & Shamed Logo Manager