MyD Delivery Widgets Security & Risk Analysis

wordpress.org/plugins/myd-delivery-widgets

Add powerful Elementor widgets for the MyD Delivery plugin — the complete WordPress delivery system for restaurants, cafés, bakeries, and local busine …

700 active installs v1.8 PHP 7.4+ WP 5.5+ Updated Jan 29, 2026
deliveryelementormyd-delivery
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MyD Delivery Widgets Safe to Use in 2026?

Generally Safe

Score 100/100

MyD Delivery Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'myd-delivery-widgets' plugin version 1.8 exhibits a strong security posture. The absence of any identified attack surface entries, such as AJAX handlers, REST API routes, shortcodes, or cron events, significantly reduces the plugin's exposure to external attacks. Furthermore, the code analysis reveals no dangerous functions, file operations, or external HTTP requests, and all SQL queries are properly prepared. While the majority of output is escaped, there is a slight concern with 11% of outputs not being properly escaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. The plugin also lacks nonce and capability checks, which, in the absence of other entry points, is not a significant immediate risk but represents a missed opportunity for robust security layering. The complete lack of recorded vulnerabilities or CVEs, both historically and currently, is a very positive indicator of the developer's commitment to security or the plugin's inherent simplicity and low risk.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

MyD Delivery Widgets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MyD Delivery Widgets Release Timeline

v1.8.0
v1.7
v1.6.2
v1.6.1
v1.6
v1.5.1
v1.5
v1.4
v1.3.1
v1.3
v1.2
v1.1
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

MyD Delivery Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped9 total outputs
Attack Surface

MyD Delivery Widgets Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionelementor/widgets/registerincludes\class-register-widgets.php:23
actionadmin_noticesmyd-delivery-widgets.php:40
actionadmin_noticesmyd-delivery-widgets.php:45
Maintenance & Trust

MyD Delivery Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 29, 2026
PHP min version7.4
Downloads12K

Community Trust

Rating100/100
Number of ratings1
Active installs700
Developer Profile

MyD Delivery Widgets Developer Profile

Eduardo Villão

5 plugins · 9K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MyD Delivery Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about MyD Delivery Widgets