Logo Manager For Enamad Security & Risk Analysis

wordpress.org/plugins/logo-manager-for-enamad

جهت قراردادن خودکار لوگوی نماد الکترونیکی( اینماد ) در سایت| قابلیت کدکوتاه و ابزارک برای ای نماد | شامد | نماد های دیگر

6K active installs v0.7.4 PHP + WP 3.0+ Updated Jan 29, 2025
enamadenamad-logoshamedshamed-logowordpress-enamad-plugin
91
A · Safe
CVEs total2
Unpatched0
Last CVEAug 27, 2024
Download
Safety Verdict

Is Logo Manager For Enamad Safe to Use in 2026?

Generally Safe

Score 91/100

Logo Manager For Enamad has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Aug 27, 2024Updated 1yr ago
Risk Assessment

The "logo-manager-for-enamad" plugin v0.7.4 exhibits a mixed security posture. On the positive side, the code analysis reveals good practices such as 100% of SQL queries using prepared statements and the absence of file operations or external HTTP requests. Nonce checks are present, which is a positive sign for security. However, a significant concern is the low percentage of properly escaped output (61%), indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's vulnerability history. The lack of capability checks for any entry points, though the static analysis reports 0 unprotected entry points, warrants further investigation as capability checks are crucial for securing administrative functions.

The vulnerability history is a key area of concern. The plugin has a history of two medium-severity CVEs, specifically related to Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). The fact that these vulnerabilities, though not currently unpatched, have existed suggests a pattern of past security weaknesses. The most recent vulnerability was on August 27, 2024, which is very recent and highlights an ongoing security challenge.

In conclusion, while the plugin demonstrates some good coding practices like prepared SQL statements, the high proportion of unescaped output and the history of XSS and CSRF vulnerabilities are significant weaknesses. The lack of explicit capability checks on entry points, even if static analysis shows them as protected, remains a point of caution. Users should be aware of the potential for XSS and CSRF if the unescaped output vulnerabilities are not thoroughly addressed.

Key Concerns

  • Medium severity CVEs in vulnerability history
  • Significant portion of output not properly escaped
  • Recent vulnerability reported
Vulnerabilities
2

Logo Manager For Enamad Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-5170medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Logo Manager For Enamad <= 0.7.2 - Authenticated (Admin+) Stored Cross-Site Scripting

Aug 27, 2024 Patched in 0.7.3 (70d)
CVE-2024-4757medium · 6.1Cross-Site Request Forgery (CSRF)

Logo Manager For Enamad <= 0.7.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Jun 4, 2024 Patched in 0.7.1 (42d)
Code Analysis
Analyzed Mar 16, 2026

Logo Manager For Enamad Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
27 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

61% escaped44 total outputs
Attack Surface

Logo Manager For Enamad Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[enamadlogo_shortcode] fns.php:25
[enamadlogo_shamed_shortcode] fns.php:44
[enamadlogo_custom_shortcode] fns.php:63
WordPress Hooks 9
actionwp_footerfns.php:73
actionadmin_initfns.php:176
actionadmin_noticesfns.php:180
actioninitfns.php:225
actionadmin_menusimple-class-options.php:27
actionwidgets_initwidgets.php:63
actionwidgets_initwidgets.php:129
actionwidgets_initwidgets.php:195
actioninitwidgets.php:225
Maintenance & Trust

Logo Manager For Enamad Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 29, 2025
PHP min version
Downloads80K

Community Trust

Rating88/100
Number of ratings7
Active installs6K
Developer Profile

Logo Manager For Enamad Developer Profile

Omid Shamloo

7 plugins · 8K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
158 days
View full developer profile
Detection Fingerprints

How We Detect Logo Manager For Enamad

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/logo-manager-for-enamad/css/enamadlogo.css/wp-content/plugins/logo-manager-for-enamad/js/enamadlogo.js
Script Paths
/wp-content/plugins/logo-manager-for-enamad/js/enamadlogo.js
Version Parameters
logo-manager-for-enamad/css/enamadlogo.css?ver=logo-manager-for-enamad/js/enamadlogo.js?ver=

HTML / DOM Fingerprints

CSS Classes
enamad-logo-widget
HTML Comments
<!--No script kiddies please!-->
Data Attributes
name="enamad-enable"name="enamad-disable-mobile"name="enamad-replace-with-img"name="enamad-width"name="enamad-position"name="enamad-view-method"+6 more
FAQ

Frequently Asked Questions about Logo Manager For Enamad