
Employee Directory – Staff Directory and Listing Security & Risk Analysis
wordpress.org/plugins/employee-staff-directoryWordPress Employee Directory plugin builds Employee directory, Member/Staff directory, Employee listings & displays the Staff list [24/7 SUPPORT]
Is Employee Directory – Staff Directory and Listing Safe to Use in 2026?
Generally Safe
Score 99/100Employee Directory – Staff Directory and Listing has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "employee-staff-directory" plugin v1.2.2 exhibits a generally good security posture based on static analysis. The absence of dangerous functions, the use of prepared statements for all SQL queries, and a high percentage of properly escaped output are positive indicators. Furthermore, the presence of nonce and capability checks on its identified entry points (shortcodes) suggests an effort to protect against common attack vectors. The plugin also has no critical or high severity known vulnerabilities, and importantly, all past vulnerabilities are currently patched.
However, a few areas warrant caution. The static analysis reveals one flow with an unsanitized path, which, despite not being categorized as critical or high severity in the taint analysis, represents a potential weakness. While the attack surface is small and all identified entry points have some form of protection, the existence of this unsanitized path is a concern. The plugin's history of a medium severity vulnerability, even though patched, indicates that past issues have occurred, with the most recent one being a Cross-site Scripting vulnerability. This suggests a need for continued vigilance and thorough code review.
In conclusion, the plugin demonstrates several strengths in secure coding practices. The primary concern lies in the single identified unsanitized path flow, which, while not overtly critical based on the provided data, should be investigated and mitigated. The history of a medium severity XSS vulnerability, although resolved, highlights the importance of ongoing security maintenance. Overall, the plugin is relatively secure but not without areas requiring attention.
Key Concerns
- Flows with unsanitized paths
- 1 medium severity vulnerability in history
Employee Directory – Staff Directory and Listing Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Employee Directory <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_title' Shortcode Attribute
Employee Directory – Staff Directory and Listing Release Timeline
Employee Directory – Staff Directory and Listing Code Analysis
Output Escaping
Data Flow Analysis
Employee Directory – Staff Directory and Listing Attack Surface
Shortcodes 4
WordPress Hooks 26
Maintenance & Trust
Employee Directory – Staff Directory and Listing Maintenance & Trust
Maintenance Signals
Community Trust
Employee Directory – Staff Directory and Listing Alternatives
Business Directory Plugin – Easy Listing Directories for WordPress
business-directory-plugin
The easy Business Directory Plugin for WordPress. Build an easy team directory, member directory, staff directory, church directory, and more.
Contact List – Online Staff Directory & Address Book
contact-list
Build a custom staff directory, address book or any kind of listing with this easy-to-use plugin.
Directorist: AI-Powered Business Directory, Listings & Classified Ads
directorist
Build any type of directory website such as a business directory, job directory, classifieds directory, and more with this WordPress directory plugin.
Classified Listing – AI-Powered Classified ads & Business Directory Plugin
classified-listing
A Classified ads and Business Directory plugin for WordPress, to create classified listing, real estate directory, local business directory, and more.
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
geodirectory
A superb WordPress Business Directory plugin to create a local business directory, classified ads directory, or job listings board.
Employee Directory – Staff Directory and Listing Developer Profile
41 plugins · 83K total installs
How We Detect Employee Directory – Staff Directory and Listing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/employee-staff-directory/assets/css/mo_employee.css/wp-content/plugins/employee-staff-directory/assets/css/style_settings.min.css/wp-content/plugins/employee-staff-directory/assets/css/bootstrap.min.css/wp-content/plugins/employee-staff-directory/assets/css/datetime-style-settings.min.css/wp-content/plugins/employee-staff-directory/assets/css/jquery-ui.min.css/wp-content/plugins/employee-staff-directory/assets/css/phone.min.css/wp-content/plugins/employee-staff-directory/assets/js/phone.min.js/wp-content/plugins/employee-staff-directory/assets/js/views.jshttps://cdnjs.cloudflare.com/ajax/libs/jquery/3.1.1/jquery.min.jshttps://cdnjs.cloudflare.com/ajax/libs/select2/4.0.3/js/select2.min.jshttps://cdnjs.cloudflare.com/ajax/libs/timepicker/1.3.5/jquery.timepicker.min.jsemployee-staff-directory/assets/css/mo_employee.css?ver=employee-staff-directory/assets/css/style_settings.min.css?ver=employee-staff-directory/assets/css/bootstrap.min.css?ver=employee-staff-directory/assets/css/datetime-style-settings.min.css?ver=employee-staff-directory/assets/css/jquery-ui.min.css?ver=employee-staff-directory/assets/css/phone.min.css?ver=employee-staff-directory/assets/js/phone.min.js?ver=employee-staff-directory/assets/js/views.js?ver=HTML / DOM Fingerprints
mo_empdir_formmo_empdir_search_containermo_empdir_member_profilemo_empdir_member_detailsmo_empdir_employee_listmo_empdir_layout_optionsmo_empdir_settings_tab<!-- Plugin Name: Employee Staff Directory -->data-post-type="employee-directory"data-taxonomy="employee-directory-department"data-taxonomy="employee-directory-gender"data-taxonomy="employee-directory-etype"mo_empdir_options_plugin_constants/wp-json/employee-directory/v1/departments/wp-json/employee-directory/v1/genders/wp-json/employee-directory/v1/employment-types[employee-directory-list][employee-directory-search][employee-directory-profile]