NetLeader Aviator Security & Risk Analysis

wordpress.org/plugins/netleader-aviator

Aircraft Weight and Balance calculator for flying clubs and organizations.

10 active installs v1.1.5 PHP + WP 4.9+ Updated Dec 10, 2024
aircraftaviationaviatorcalculatornetleader
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NetLeader Aviator Safe to Use in 2026?

Generally Safe

Score 92/100

NetLeader Aviator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "netleader-aviator" plugin v1.1.5 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by ensuring all identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) are either absent or protected by appropriate checks. Notably, all output is properly escaped, and there are no identified dangerous functions or external HTTP requests, which are common vectors for exploits. The absence of any known vulnerabilities or CVEs in its history further reinforces this positive assessment, suggesting diligent security awareness from the developers.

However, a key concern arises from the SQL query handling. With 7 total SQL queries and only 14% utilizing prepared statements, there is a significant risk of SQL injection vulnerabilities. This is a critical oversight as raw SQL queries are highly susceptible to malicious input. Additionally, the complete absence of nonce checks, even with capability checks in place, leaves a potential opening for Cross-Site Request Forgery (CSRF) attacks if an attacker can trick a logged-in user into performing an action. While the plugin has a clean history and good output sanitization, these specific code issues introduce notable risks that require attention.

Key Concerns

  • SQL queries not using prepared statements
  • Missing nonce checks
Vulnerabilities
None known

NetLeader Aviator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

NetLeader Aviator Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
1 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
4
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

14% prepared7 total queries

Output Escaping

100% escaped5 total outputs
Attack Surface

NetLeader Aviator Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[netleader_aviator] netleader-aviator.php:888
WordPress Hooks 1
actionwp_enqueue_scriptsnetleader-aviator.php:890
Maintenance & Trust

NetLeader Aviator Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 10, 2024
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

NetLeader Aviator Developer Profile

NetLeader

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NetLeader Aviator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/netleader-aviator/js/jquery.serializeall.js/wp-content/plugins/netleader-aviator/js/netleader-aviator.js/wp-content/plugins/netleader-aviator/css/netleader-aviator.css
Script Paths
/wp-content/plugins/netleader-aviator/js/jquery.serializeall.js/wp-content/plugins/netleader-aviator/js/netleader-aviator.js
Version Parameters
netleader-aviator/js/jquery.serializeall.js?ver=netleader-aviator/js/netleader-aviator.js?ver=netleader-aviator/css/netleader-aviator.css?ver=

HTML / DOM Fingerprints

CSS Classes
nlavprofnlavdesctabnlavctrnlavdescnlavinpnlavweightnlavcgnlavlabel+6 more
Data Attributes
data-profiledata-weightdata-cg
JS Globals
jQueryacParamscanEditshowEditmodProfilesqlID+20 more
Shortcode Output
<div id="acprofiles"></div><div id="acdescription"></div><div id="statusmsg"></div><div id="acsummary"></div>
FAQ

Frequently Asked Questions about NetLeader Aviator