Listdomer Core – Core of Listdomer Theme Security & Risk Analysis

wordpress.org/plugins/listdomer-core

Listdomer Core plugin adds some awesome functionality to Webilia Listdomer Theme.

500 active installs v4.1.0 PHP 7.4+ WP 4.2+ Updated Feb 28, 2026
business-directoryclassifiedslistdomlistdomerlistings
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Listdomer Core – Core of Listdomer Theme Safe to Use in 2026?

Generally Safe

Score 100/100

Listdomer Core – Core of Listdomer Theme has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'listdomer-core' plugin v4.1.0 presents a concerning security posture primarily due to its unprotected entry points. With two AJAX handlers identified and neither possessing authentication checks, there's a significant risk of unauthorized actions being performed. The absence of any capability checks further exacerbates this, meaning any authenticated user, regardless of their role, could potentially trigger these handlers. While the static analysis shows a reasonable rate of output escaping and no critical or high-severity taint flows, the lack of input validation on the unprotected AJAX endpoints is a major red flag. The plugin's vulnerability history is clean, with no recorded CVEs. This could indicate either a well-developed plugin or simply a lack of past security scrutiny. However, the current code analysis reveals clear weaknesses that could be exploited, making the clean history less reassuring. The plugin's strengths lie in its minimal use of dangerous functions and lack of bundled libraries. Nevertheless, the two unprotected AJAX handlers without any form of authorization or capability checks represent a critical security vulnerability that needs immediate attention.

Key Concerns

  • AJAX handlers without auth checks
  • No capability checks on entry points
  • SQL queries without prepared statements
  • Moderate rate of unescaped output
Vulnerabilities
None known

Listdomer Core – Core of Listdomer Theme Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Listdomer Core – Core of Listdomer Theme Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
43
192 escaped
Nonce Checks
3
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

82% escaped235 total outputs
Attack Surface
2 unprotected

Listdomer Core – Core of Listdomer Theme Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_lsdrc_logisterapp\includes\hooks.php:48
noprivwp_ajax_lsdrc_logisterapp\includes\hooks.php:49
WordPress Hooks 31
actionelementor/widgets/registerapp\includes\elementor.php:12
actionelementor/initapp\includes\elementor.php:15
actionelementor/documents/registerapp\includes\elementor.php:18
filterlsdr_header_typesapp\includes\elementor.php:21
filterlsdr_footer_typesapp\includes\elementor.php:22
actionafter_setup_themeapp\includes\hooks.php:42
actioninitapp\includes\hooks.php:43
actionwp_enqueue_scriptsapp\includes\hooks.php:44
actionlistdomer_header_buttonsapp\includes\hooks.php:47
actionadmin_enqueue_scriptsapp\includes\hooks.php:58
actionadmin_initapp\includes\hooks.php:70
actionadd_meta_boxesapp\includes\hooks.php:86
actionsave_postapp\includes\hooks.php:87
filterlsd_templateapp\includes\hooks.php:107
filterlsdaddclm_display_verifiedapp\includes\hooks.php:108
filterlsdaddclm_claim_textapp\includes\hooks.php:109
actioninitapp\includes\i18n.php:8
actionadmin_menuapp\includes\menus.php:8
filterocdi/import_filesapp\includes\ocdi.php:10
filterocdi/register_pluginsapp\includes\ocdi.php:13
actionocdi/before_widgets_importapp\includes\ocdi.php:16
actionocdi/before_content_importapp\includes\ocdi.php:17
actionocdi/after_importapp\includes\ocdi.php:20
filterocdi/plugin_page_setupapp\includes\ocdi.php:23
filterocdi/plugin_intro_textapp\includes\ocdi.php:26
filterocdi/plugin_page_titleapp\includes\ocdi.php:27
filterocdi/import_successful_buttonsapp\includes\ocdi.php:28
actionafter_setup_themeapp\includes\settings.php:14
filtertheme_page_templatesapp\includes\settings.php:16
filtertheme_post_templatesapp\includes\settings.php:17
actionwidgets_initapp\includes\widgets.php:7
Maintenance & Trust

Listdomer Core – Core of Listdomer Theme Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 28, 2026
PHP min version7.4
Downloads18K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

Listdomer Core – Core of Listdomer Theme Developer Profile

Webilia Inc.

7 plugins · 2K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Listdomer Core – Core of Listdomer Theme

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/listdomer-core/assets/css/wp-backend.css
Script Paths
/wp-content/plugins/listdomer-core/assets/js/logister.min.js
Version Parameters
listdomer-core/assets/css/wp-backend.css?ver=logister.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
lsd-metaboxlsdrp-metaboxlsd-mb-3post-attributes-label-wrapper
Data Attributes
name="lsdr[header]"id="lsdr_header"name="lsdr[footer]"id="lsdr_footer"
JS Globals
lsdrcLogister
FAQ

Frequently Asked Questions about Listdomer Core – Core of Listdomer Theme