
Logo and Address Widget with Schema Security & Risk Analysis
wordpress.org/plugins/logo-and-address-widget-with-schemaAre you still trying to show your business address in the plain text widget? Are you tired of adding custom CSS to make your business hours look good …
Is Logo and Address Widget with Schema Safe to Use in 2026?
Generally Safe
Score 85/100Logo and Address Widget with Schema has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "logo-and-address-widget-with-schema" plugin v2.9 exhibits a mixed security posture. On the positive side, it shows excellent practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerabilities in its history, suggesting a generally stable codebase. The absence of file operations and external HTTP requests further limits potential attack vectors.
However, significant concerns arise from the static analysis. The plugin presents a single AJAX entry point that lacks any authentication or authorization checks, making it a prime target for unauthorized access or execution. Furthermore, a concerning 43% of output operations are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially when combined with the unprotected AJAX handler. The lack of nonce checks on the AJAX endpoint exacerbates this risk. While taint analysis shows no explicit flows, the combination of unprotected AJAX and unescaped output creates a dangerous environment.
In conclusion, while the plugin demonstrates good SQL hygiene and a clean vulnerability history, the unprotected AJAX handler and widespread unescaped output represent critical security weaknesses that require immediate attention. The plugin's strengths in SQL and vulnerability history are overshadowed by these fundamental security oversights.
Key Concerns
- Unprotected AJAX handler found
- Significant unescaped output (43%)
- Missing nonce checks on AJAX handler
Logo and Address Widget with Schema Security Vulnerabilities
Logo and Address Widget with Schema Code Analysis
Output Escaping
Logo and Address Widget with Schema Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Logo and Address Widget with Schema Maintenance & Trust
Maintenance Signals
Community Trust
Logo and Address Widget with Schema Alternatives
No alternatives data available yet.
Logo and Address Widget with Schema Developer Profile
4 plugins · 720 total installs
How We Detect Logo and Address Widget with Schema
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/logo-and-address-widget-with-schema/js/laawws-media-upload.js/wp-content/plugins/logo-and-address-widget-with-schema/css/laawws-custom.css/wp-content/plugins/logo-and-address-widget-with-schema/js/laawws-media-upload.jslogo-and-address-widget-with-schema/js/laawws-media-upload.js?ver=logo-and-address-widget-with-schema/css/laawws-custom.css?ver=HTML / DOM Fingerprints
laawws_widget_titlelaawws_footer_logolaawws_image_radio_buttonslaawws_address_line1laawws_citylaawws_statelaawws_ziplaawws_address_radio_buttons+22 moredata-laawws_fawesome_icondata-laawws_custom_imagedata-laawws_epf_radio_buttonsdata-laawws_open_hoursdata-laawws_open_hours_titledata-laawws_open_hours_mon_fri+14 morelaawws_media_uploadlaawws_time_picker/wp-json/logo-and-address-widget-with-schema/v1/list_items