Explara Lite Security & Risk Analysis

wordpress.org/plugins/explara-lite

Managing events shouldn’t be complex and costly. Now integrate the power of Explara to your existing WordPress site with the Explara Lite Plugin.

10 active installs v0.1.3 PHP + WP 4.6+ Updated Dec 5, 2019
eventsexplaragroupsmembers
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Explara Lite Safe to Use in 2026?

Generally Safe

Score 85/100

Explara Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "explara-lite" plugin version 0.1.3 exhibits significant security concerns due to a large number of unprotected entry points. With 5 out of 7 total entry points lacking authentication checks, there is a high risk of unauthorized access and potential abuse. While the plugin avoids dangerous functions and utilizes prepared statements for SQL queries, the extremely low percentage of properly escaped output (2%) is a major red flag, indicating a strong likelihood of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis revealing flows with unsanitized paths further supports this concern, even without critical or high severity findings. The absence of any recorded vulnerability history might suggest a lack of exploitation or discovery, but this should not be interpreted as a sign of robust security given the static analysis findings.

In conclusion, the plugin's security posture is weak. The presence of numerous unprotected AJAX handlers combined with severe output escaping deficiencies creates a critical attack surface. Although there are no known CVEs or critical taint findings, the inherent design flaws, particularly the lack of nonce and capability checks on AJAX actions, make it highly susceptible to common web attacks like XSS and potentially unauthorized actions. Users should proceed with extreme caution and consider alternatives or ensure robust additional security measures are in place.

Key Concerns

  • 5 unprotected AJAX handlers
  • 2% properly escaped output
  • 3 flows with unsanitized paths
  • 0 Nonce checks
  • 0 Capability checks
Vulnerabilities
None known

Explara Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Explara Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
82
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

2% escaped84 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
saveToken (includes\admin\explara-admin-post.php:23)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Explara Lite Attack Surface

Entry Points7
Unprotected5

AJAX Handlers 5

authwp_ajax_page_add_tokenincludes\admin\explara-admin-post.php:5
authwp_ajax_page_add_domainincludes\admin\explara-admin-post.php:6
authwp_ajax_page_shortcode_eventsincludes\admin\explara-admin-post.php:8
authwp_ajax_page_shortcode_groupincludes\admin\explara-admin-post.php:9
authwp_ajax_get_memberships_typeincludes\admin\explara-admin-post.php:10

Shortcodes 2

[explara-events] includes\member\explara-shortcodes-events.php:5
[explara-group] includes\member\explara-shortcodes-members.php:5
WordPress Hooks 4
actioninitexplara-lite.php:70
actionadmin_menuincludes\admin\explara-admin.php:23
actionadmin_noticesincludes\admin\explara-admin.php:29
actionadmin_enqueue_scriptsincludes\admin\explara-admin.php:44
Maintenance & Trust

Explara Lite Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedDec 5, 2019
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Explara Lite Developer Profile

Explara

2 plugins · 20 total installs

77
trust score
Avg Security Score
75/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Explara Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/explara-lite/public/css/admin.css/wp-content/plugins/explara-lite/public/js/min/admin-min.js/wp-content/plugins/explara-lite/public/css/member.css
Script Paths
/wp-content/plugins/explara-lite/public/js/min/admin-min.js
Version Parameters
explara-lite/public/css/admin.css?ver=explara-lite/public/css/member.css?ver=explara-lite/public/js/min/admin-min.js?ver=

HTML / DOM Fingerprints

JS Globals
EXPAjax
Shortcode Output
[explara-events][explara-group]
FAQ

Frequently Asked Questions about Explara Lite