Logo and Address Widget with Schema Security & Risk Analysis

wordpress.org/plugins/logo-and-address-widget-with-schema

Are you still trying to show your business address in the plain text widget? Are you tired of adding custom CSS to make your business hours look good …

100 active installs v2.9 PHP + WP 4.7.5+ Updated Feb 10, 2023
address-widget-with-schemalogo-address-widgetlogo-address-widget-with-schemalogo-and-addressmanage-different-locations
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Logo and Address Widget with Schema Safe to Use in 2026?

Generally Safe

Score 85/100

Logo and Address Widget with Schema has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "logo-and-address-widget-with-schema" plugin v2.9 exhibits a mixed security posture. On the positive side, it shows excellent practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerabilities in its history, suggesting a generally stable codebase. The absence of file operations and external HTTP requests further limits potential attack vectors.

However, significant concerns arise from the static analysis. The plugin presents a single AJAX entry point that lacks any authentication or authorization checks, making it a prime target for unauthorized access or execution. Furthermore, a concerning 43% of output operations are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially when combined with the unprotected AJAX handler. The lack of nonce checks on the AJAX endpoint exacerbates this risk. While taint analysis shows no explicit flows, the combination of unprotected AJAX and unescaped output creates a dangerous environment.

In conclusion, while the plugin demonstrates good SQL hygiene and a clean vulnerability history, the unprotected AJAX handler and widespread unescaped output represent critical security weaknesses that require immediate attention. The plugin's strengths in SQL and vulnerability history are overshadowed by these fundamental security oversights.

Key Concerns

  • Unprotected AJAX handler found
  • Significant unescaped output (43%)
  • Missing nonce checks on AJAX handler
Vulnerabilities
None known

Logo and Address Widget with Schema Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Logo and Address Widget with Schema Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
177
132 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

43% escaped309 total outputs
Attack Surface
1 unprotected

Logo and Address Widget with Schema Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_list_itemslogo-and-address-widget-with-schema.php:87
WordPress Hooks 3
actionwidgets_initlogo-and-address-widget-with-schema.php:48
actionadmin_enqueue_scriptslogo-and-address-widget-with-schema.php:49
actioninitlogo-and-address-widget-with-schema.php:50
Maintenance & Trust

Logo and Address Widget with Schema Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 10, 2023
PHP min version
Downloads12K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Alternatives

Logo and Address Widget with Schema Alternatives

No alternatives data available yet.

Developer Profile

Logo and Address Widget with Schema Developer Profile

wsxplugindev

4 plugins · 720 total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
253 days
View full developer profile
Detection Fingerprints

How We Detect Logo and Address Widget with Schema

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logo-and-address-widget-with-schema/js/laawws-media-upload.js/wp-content/plugins/logo-and-address-widget-with-schema/css/laawws-custom.css
Script Paths
/wp-content/plugins/logo-and-address-widget-with-schema/js/laawws-media-upload.js
Version Parameters
logo-and-address-widget-with-schema/js/laawws-media-upload.js?ver=logo-and-address-widget-with-schema/css/laawws-custom.css?ver=

HTML / DOM Fingerprints

CSS Classes
laawws_widget_titlelaawws_footer_logolaawws_image_radio_buttonslaawws_address_line1laawws_citylaawws_statelaawws_ziplaawws_address_radio_buttons+22 more
Data Attributes
data-laawws_fawesome_icondata-laawws_custom_imagedata-laawws_epf_radio_buttonsdata-laawws_open_hoursdata-laawws_open_hours_titledata-laawws_open_hours_mon_fri+14 more
JS Globals
laawws_media_uploadlaawws_time_picker
REST Endpoints
/wp-json/logo-and-address-widget-with-schema/v1/list_items
FAQ

Frequently Asked Questions about Logo and Address Widget with Schema