Multislot Business Hours for Dokan Vendor Security & Risk Analysis

wordpress.org/plugins/multislot-business-hours-for-dokan-vendor

Enable multislot business hours / multislot opening and closing times for each workday for your vendor store with this plugin.

10 active installs v1.0.1.6 PHP 5.6+ WP 4.4+ Updated Mar 1, 2022
business-hoursdokanopen-closestore-openvendor-open-close
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Multislot Business Hours for Dokan Vendor Safe to Use in 2026?

Generally Safe

Score 85/100

Multislot Business Hours for Dokan Vendor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "multislot-business-hours-for-dokan-vendor" plugin, in version 1.0.1.6, presents a generally positive security posture, characterized by a lack of known vulnerabilities and a clean taint analysis. The plugin demonstrates good practices in handling SQL queries exclusively through prepared statements and a high percentage of properly escaped output, indicating an awareness of common web security pitfalls. Furthermore, the absence of external HTTP requests and file operations reduces the potential for attack vectors originating from these areas.

However, a significant concern arises from the presence of the "unserialize" function, which is often associated with deserialization vulnerabilities. While the static analysis reports no exploitable flows, this function represents a potential danger if it's used with untrusted user input, particularly in conjunction with other potential weaknesses that might not be immediately apparent in the provided static analysis. The lack of nonce and capability checks, while not directly flagged as exploitable in this analysis due to the zero attack surface in AJAX, REST API, and shortcodes, could become a liability if future versions introduce new entry points without adequate authentication or authorization mechanisms.

Given the absence of any recorded vulnerabilities, the plugin's history suggests a commitment to security or a fortunate lack of past issues. The current analysis reveals a plugin that adheres to many security best practices, but the presence of a dangerous function like "unserialize" without clear context on its usage and the absence of some fundamental security checks (like nonces and capabilities) on its limited entry points introduce a calculated risk. Future development should focus on thoroughly auditing the "unserialize" usage and ensuring robust security checks are implemented for any new or existing entry points.

Key Concerns

  • Dangerous function detected (unserialize)
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Multislot Business Hours for Dokan Vendor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Multislot Business Hours for Dokan Vendor Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
4
69 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$profile_settings = unserialize($doc_fetched_posts[$product->get_id()]->dokan_profile_settings);core\product-actions.php:88

Output Escaping

95% escaped73 total outputs
Attack Surface

Multislot Business Hours for Dokan Vendor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionwoocommerce_before_add_to_cart_formcore\product-actions.php:39
actiondokan_seller_listing_footer_contentcore\product-actions.php:40
actionpre_get_postscore\product-actions.php:41
filterposts_fieldscore\product-actions.php:42
filterposts_joincore\product-actions.php:43
filterposts_wherecore\product-actions.php:44
actionthe_postcore\product-actions.php:45
actionwoocommerce_after_shop_loop_itemcore\product-actions.php:46
filterdokan_settings_fieldscore\promo.php:4
filterdokan_save_settings_valuecore\store-settings.php:38
filterdokan_settings_fieldscore\store-settings.php:39
actiondokan_settings_form_bottomcore\store-settings.php:40
actiondokan_store_profile_savedcore\store-settings.php:41
actiondokan_store_header_info_fieldscore\store.php:38
filterdokan_widgetscore\widget-actions.php:39
actioninitmultislot-business-hours-for-dokan-vendor.php:77
filterplugin_action_links_multislot-business-hours-for-dokan-vendor/multislot-business-hours-for-dokan-vendor.phpmultislot-business-hours-for-dokan-vendor.php:80
Maintenance & Trust

Multislot Business Hours for Dokan Vendor Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedMar 1, 2022
PHP min version5.6
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Multislot Business Hours for Dokan Vendor Developer Profile

Mithu A Quayium

16 plugins · 500 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Multislot Business Hours for Dokan Vendor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multislot-business-hours-for-dokan-vendor/assets/css/style.css/wp-content/plugins/multislot-business-hours-for-dokan-vendor/assets/js/main.js/wp-content/plugins/multislot-business-hours-for-dokan-vendor/assets/css/daterangepicker.css/wp-content/plugins/multislot-business-hours-for-dokan-vendor/assets/js/daterangepicker.js/wp-content/plugins/multislot-business-hours-for-dokan-vendor/assets/js/moment.min.js/wp-content/plugins/multislot-business-hours-for-dokan-vendor/assets/js/multi-select.js/wp-content/plugins/multislot-business-hours-for-dokan-vendor/assets/css/multi-select.css
Script Paths
/wp-content/plugins/multislot-business-hours-for-dokan-vendor/assets/js/main.js/wp-content/plugins/multislot-business-hours-for-dokan-vendor/assets/js/daterangepicker.js/wp-content/plugins/multislot-business-hours-for-dokan-vendor/assets/js/moment.min.js/wp-content/plugins/multislot-business-hours-for-dokan-vendor/assets/js/multi-select.js
Version Parameters
multislot-business-hours-for-dokan-vendor/assets/css/style.css?ver=multislot-business-hours-for-dokan-vendor/assets/js/main.js?ver=multislot-business-hours-for-dokan-vendor/assets/css/daterangepicker.css?ver=multislot-business-hours-for-dokan-vendor/assets/js/daterangepicker.js?ver=multislot-business-hours-for-dokan-vendor/assets/js/moment.min.js?ver=multislot-business-hours-for-dokan-vendor/assets/js/multi-select.js?ver=multislot-business-hours-for-dokan-vendor/assets/css/multi-select.css?ver=

HTML / DOM Fingerprints

CSS Classes
doc-store-noticedoc-store-notice-opendoc-store-notice-close
Data Attributes
data-dokan-store-id
JS Globals
dokan_multislot_business_hours_data
FAQ

Frequently Asked Questions about Multislot Business Hours for Dokan Vendor