
GoToBIM Business Info Manager Security & Risk Analysis
wordpress.org/plugins/gotobim-business-infoEasily manage and display your company's business information including name, address, phone, email, website, and business hours from WordPress admin.
Is GoToBIM Business Info Manager Safe to Use in 2026?
Generally Safe
Score 100/100GoToBIM Business Info Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gotobim-business-info v1.1.0 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and properly escaping the vast majority of its output. The absence of file operations and external HTTP requests further minimizes potential attack vectors. The plugin also has no recorded vulnerability history, indicating a potentially stable and well-maintained codebase.
However, the static analysis reveals a significant concern: the complete lack of nonce checks and capability checks across all identified entry points. While the attack surface is small (one shortcode) and currently has no AJAX or REST API endpoints without authentication, this absence of checks is a critical oversight. Should the plugin evolve to include user-interactive features or if the shortcode's functionality is ever extended to handle user-supplied data, the lack of nonce and capability checks could expose the site to CSRF (Cross-Site Request Forgery) and unauthorized privilege escalation vulnerabilities. The taint analysis showing zero flows with unsanitized paths is positive but doesn't negate the fundamental security gaps in authorization.
In conclusion, the plugin's codebase demonstrates good technical implementation in areas like SQL and output sanitization. Its clean vulnerability history is also a positive indicator. Nevertheless, the missing nonce and capability checks represent a glaring weakness that requires immediate attention, as it leaves the plugin susceptible to common web vulnerabilities if its functionality is ever expanded or exploited in unexpected ways. The small attack surface currently mitigates immediate risk, but this is a ticking time bomb.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Minor output unescaped (7% of outputs)
GoToBIM Business Info Manager Security Vulnerabilities
GoToBIM Business Info Manager Release Timeline
GoToBIM Business Info Manager Code Analysis
Output Escaping
GoToBIM Business Info Manager Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
GoToBIM Business Info Manager Maintenance & Trust
Maintenance Signals
Community Trust
GoToBIM Business Info Manager Alternatives
A1 Tools
a1-tools
Centrally manage contact information, social media links, and business details across your WordPress sites from the A1 Tools platform.
Aikezi Solutions
aikezi-solutions
The main function of this plugin is to use shortcodes to display your website's logo, image or contact information anywhere.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
GoToBIM Business Info Manager Developer Profile
1 plugin · 0 total installs
How We Detect GoToBIM Business Info Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gotobim-business-info/assets/css/admin-styles.css/wp-content/plugins/gotobim-business-info/assets/css/frontend-styles.cssHTML / DOM Fingerprints
gotobim-hours-tablename="gotobim_business_info[business_hours][name="gotobim_business_info[id="business_name"id="address"id="phone"id="email"+1 more[gotobim_business_info]