
OnList Security & Risk Analysis
wordpress.org/plugins/onlistFast and easy setup to get online listing site or directory started.
Is OnList Safe to Use in 2026?
Generally Safe
Score 92/100OnList has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The onlist plugin v1.0.8 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries, implementing a significant number of capability checks, and including a nonce check. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design. The attack surface is minimal, with only two shortcodes identified, and critically, there are no unprotected entry points. Furthermore, the taint analysis shows no identified flows with unsanitized paths, indicating a lack of immediate critical or high-severity vulnerabilities within the analyzed code.
The vulnerability history is also entirely clear, with no known CVEs, unpatched vulnerabilities, or past security incidents. This suggests a history of careful development and maintenance. However, a minor concern arises from the output escaping metric, where 19% of outputs are not properly escaped. While this does not currently appear to be exploited or lead to critical vulnerabilities, it represents a potential area for improvement and could, in specific circumstances or with future code changes, lead to cross-site scripting (XSS) vulnerabilities.
In conclusion, onlist v1.0.8 is a well-secured plugin with a clean track record and robust code practices. The primary area for attention is the unescaped output, which, while not a critical flaw at this time, should be addressed to further harden the plugin against potential XSS attacks. Overall, the plugin presents a low risk to WordPress installations.
Key Concerns
- Unescaped output present
OnList Security Vulnerabilities
OnList Code Analysis
Output Escaping
OnList Attack Surface
Shortcodes 2
WordPress Hooks 20
Maintenance & Trust
OnList Maintenance & Trust
Maintenance Signals
Community Trust
OnList Alternatives
Directorist: AI-Powered Business Directory, Listings & Classified Ads
directorist
Build any type of directory website such as a business directory, job directory, classifieds directory, and more with this WordPress directory plugin.
Classified Listing – AI-Powered Classified ads & Business Directory Plugin
classified-listing
A Classified ads and Business Directory plugin for WordPress, to create classified listing, real estate directory, local business directory, and more.
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
geodirectory
A superb WordPress Business Directory plugin to create a local business directory, classified ads directory, or job listings board.
HivePress Favorites
hivepress-favorites
Allow users to keep a list of favorite listings.
HivePress Messages
hivepress-messages
Allow users to send private messages.
OnList Developer Profile
17 plugins · 2K total installs
How We Detect OnList
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/onlist/css/onlist-style.css/wp-content/plugins/onlist/css/onlist-admin.cssonlist/css/onlist-style.css?ver=onlist/css/onlist-admin.css?ver=HTML / DOM Fingerprints
onlist_countryonlist_addressonlist_cityonlist_stateonlist_zipcodeonlist_phone+3 more[onlist-listings][onlist-categories]