
Local Magic Security & Risk Analysis
wordpress.org/plugins/local-magicThe Local Magic© WordPress plugin extends the functionality of the SaaS Local Magic© to WordPress so that the local magic can be displayed o …
Is Local Magic Safe to Use in 2026?
Use With Caution
Score 54/100Local Magic has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The 'local-magic' plugin v2.9.0 presents a mixed security posture with several concerning aspects. While it shows some good practices like a high percentage of prepared SQL statements and no detected critical or high severity taint flows, the significant number of unprotected AJAX handlers (10 out of 10) is a major red flag. This large attack surface without proper authorization checks opens the door for various privilege escalation and unauthorized action vulnerabilities.
The plugin's vulnerability history is also a concern, with two known and currently unpatched CVEs, one of which is high severity. The common vulnerability types, including SQL Injection and Missing Authorization, directly correlate with the findings in the static analysis. The fact that these vulnerabilities are recent (last one in 2025) suggests an ongoing struggle with secure development practices.
Overall, the plugin's security is compromised by its unprotected entry points and its history of critical and high-severity vulnerabilities, particularly those related to authorization and SQL injection. While the static analysis did not reveal critical taint flows, the potential for exploitation due to missing authorization checks on AJAX handlers, combined with past vulnerabilities, makes this plugin a moderate to high risk.
Key Concerns
- Unprotected AJAX handlers
- Unpatched high severity CVE
- Unpatched medium severity CVE
- Low percentage of properly escaped output
- Only 1 nonce check
- Only 1 capability check
Local Magic Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Local Magic <= 2.6.0 - Unauthenticated SQL Injection
Local Magic <= 2.6.0 - Missing Authorization
Local Magic Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Local Magic Attack Surface
AJAX Handlers 10
Shortcodes 7
WordPress Hooks 10
Maintenance & Trust
Local Magic Maintenance & Trust
Maintenance Signals
Community Trust
Local Magic Alternatives
Post to Google My Business (Google Business Profile)
post-to-google-my-business
Auto-publish posts, pages & CPTs, plus manage Google Business Profile posts. All from your WordPress dashboard!
Five Star Business Profile and Schema
business-profile
Add structured data to any page or post type. Create an SEO friendly contact card with your business info and associated schema.
Bulk Page Generator – LPagery
lpagery
Effortlessly mass generate unlimited SEO-optimized pages in bulk with LPagery. Boost traffic, save time, and grow your business in just 5 minutes!
Bulk Page Generator and Mass Page Builder – Page Generator
page-generator
Bulk generate multiple Pages using dynamic content.
Local Business Schema (JSON-LD) Lite
wpspeed-localbusiness-schema
Boost Local SEO with Smart Local Business Schema JSON-LD
Local Magic Developer Profile
2 plugins · 200 total installs
How We Detect Local Magic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/local-magic/admin/setting.php/wp-content/plugins/local-magic/activate.php/wp-content/plugins/local-magic/deactivate.php/wp-content/plugins/local-magic/include/function.php/wp-content/plugins/local-magic/assets/images/icon-lm-light.pngHTML / DOM Fingerprints
mrylm_manage_pagesmrylm_update_settingmrylm_local_magic_articlemrylm_dropdown_menumrylm_newsmrylm_service_area+5 more/wp-json/local-magic/v1/feed[mrylm-article][mrylm-menu][mrylm-news][mrylm-service-area]