
Obituary Assistant Security & Risk Analysis
wordpress.org/plugins/obituary-assistant-by-funeral-home-website-solutionsAdd and Manage obituaries on your funeral home website for free.
Is Obituary Assistant Safe to Use in 2026?
Generally Safe
Score 100/100Obituary Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The obituary-assistant-by-funeral-home-website-solutions plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by having zero known CVEs, no unpatched vulnerabilities, and using prepared statements for all its SQL queries. The absence of dangerous functions and the relatively low number of file operations and external HTTP requests are also encouraging signs.
However, there are notable concerns stemming from the static analysis. A significant portion of the plugin's output is not properly escaped (only 17%), which presents a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered directly. Furthermore, two AJAX handlers are exposed without authentication checks, creating potential entry points for unauthorized actions. While the taint analysis did not reveal critical or high severity issues, the presence of two flows with unsanitized paths warrants attention, as these could potentially be exploited under certain conditions.
In conclusion, the plugin's clean vulnerability history is a strong indicator of careful development and maintenance. Nonetheless, the identified issues with output escaping and unprotected AJAX handlers represent tangible security weaknesses that should be addressed to improve its overall security posture. The plugin has a solid foundation but requires refinement in specific areas to mitigate potential risks.
Key Concerns
- High percentage of unescaped output
- Unprotected AJAX handlers
- Flows with unsanitized paths
Obituary Assistant Security Vulnerabilities
Obituary Assistant Code Analysis
Output Escaping
Data Flow Analysis
Obituary Assistant Attack Surface
AJAX Handlers 6
Shortcodes 6
WordPress Hooks 27
Maintenance & Trust
Obituary Assistant Maintenance & Trust
Maintenance Signals
Community Trust
Obituary Assistant Alternatives
WP Obituary Manager
wp-obituary
WP Obituary Manager is a free WordPress plugin that helps funeral homes, crematories, and cemeteries manage and display obituaries online.
Make My Donation – In Memory Of Platform
makemydonation-imo
Integrate your funeral home site with our Make My Donation - In Memory Of Platform and allow donations to over 1.5 million eligible US charities.
Karma Memorials
karma-memorials
Complete system for managing online obituaries and memorials with messages, search, notifications and customizable templates.
Obituary Assistant Developer Profile
1 plugin · 200 total installs
How We Detect Obituary Assistant
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/obituary-assistant-by-funeral-home-website-solutions/admin/css/jquery-ui.css/wp-content/plugins/obituary-assistant-by-funeral-home-website-solutions/admin/css/fhw-solutions-obituaries-admin.css/wp-content/plugins/obituary-assistant-by-funeral-home-website-solutions/admin/js/jquery.validate.js/wp-content/plugins/obituary-assistant-by-funeral-home-website-solutions/admin/js/fhw-solutions-obituaries-admin.js/wp-content/plugins/obituary-assistant-by-funeral-home-website-solutions/public/css/obituary-public.css/wp-content/plugins/obituary-assistant-by-funeral-home-website-solutions/public/js/obituary-public.jsjquery-ui-accordionjquery-validatefhw-solutions-obituaries-adminobituary-assistant-by-funeral-home-website-solutions/admin/css/jquery-ui.css?ver=obituary-assistant-by-funeral-home-website-solutions/admin/css/fhw-solutions-obituaries-admin.css?ver=obituary-assistant-by-funeral-home-website-solutions/admin/js/jquery.validate.js?ver=obituary-assistant-by-funeral-home-website-solutions/admin/js/fhw-solutions-obituaries-admin.js?ver=obituary-assistant-by-funeral-home-website-solutions/public/css/obituary-public.css?ver=obituary-assistant-by-funeral-home-website-solutions/public/js/obituary-public.js?ver=HTML / DOM Fingerprints
fhws_obituary_wrapper<!-- FHWS OB -->fhw_solutions_obituaries_admin_object[obituary-listing][obituary-details][obituary-submit]