
List Petfinder Pets Security & Risk Analysis
wordpress.org/plugins/petfinder-listingsThe List Petfinder Pets plugin takes advantage of the Petfinder API to list your available pets on your website.
Is List Petfinder Pets Safe to Use in 2026?
Generally Safe
Score 92/100List Petfinder Pets has a strong security track record. Known vulnerabilities have been patched promptly.
The "petfinder-listings" plugin v1.1.5 demonstrates a mixed security posture. On the positive side, the static analysis reveals no direct vulnerabilities found in taint flows or dangerous functions. The plugin also utilizes prepared statements for all its SQL queries, which is a significant best practice. However, there are areas of concern. The output escaping is not universally applied, with 23% of outputs being unescaped, potentially opening the door for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved. Furthermore, the plugin makes 10 external HTTP requests, which, if not handled securely, could be exploited for server-side request forgery (SSRF) or to fetch malicious content.
The vulnerability history, while showing no currently unpatched CVEs, indicates a past medium-severity XSS vulnerability discovered in February 2022. The presence of this type of vulnerability, coupled with the static analysis showing less than perfect output escaping, suggests a potential for similar issues to arise if code changes are not rigorously reviewed. The plugin also has a moderate attack surface with 4 shortcodes, and while no unprotected entry points were found in the static analysis, the lack of explicit capability checks on these shortcodes is a notable weakness, as it might allow unauthorized users to trigger plugin functionality.
Key Concerns
- Output escaping is not properly applied (23%)
- No capability checks found
- Previous XSS vulnerability history
- External HTTP requests (10)
List Petfinder Pets Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Petfinder Listings <= 1.0.19 - Admin+ Stored Cross-Site Scripting
List Petfinder Pets Code Analysis
Output Escaping
List Petfinder Pets Attack Surface
Shortcodes 4
WordPress Hooks 6
Maintenance & Trust
List Petfinder Pets Maintenance & Trust
Maintenance Signals
Community Trust
List Petfinder Pets Alternatives
Pet Adoption Listings
pet-adoption-listings
Display adoptable pets from an Adopt-a-Pet.com shelter's listings.
WP Petfinder
wp-petfinder
WP Petfinder plugin was designed to integrate Petfinder.com database with your Wordpress site via Petfinder API v2. It will be useful for pet shelters …
PetBridge
petbridge
Embed PetBridge features on your WordPress site to streamline pet adoptions, surrenders, alerts, and engagement with your community.
PF404 for PetFinder
pf404-for-petfinder
Overrides your 404 page template and shows dogs, cats, and other animals in need of new homes and available for adoption.
List Petfinder Pets Developer Profile
1 plugin · 400 total installs
How We Detect List Petfinder Pets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/petfinder-listings/petfinder.css/wp-content/plugins/petfinder-listings/petfinder.js/wp-content/plugins/petfinder-listings/petfinder.jspetfinder-listings/petfinder.css?ver=petfinder-listings/petfinder.js?ver=HTML / DOM Fingerprints
petfinder-listing-container<!-- Petfinder listings Shortcode --><!-- end Petfinder listings Shortcode -->data-petf-api-keydata-petf-api-secretdata-petf-shelter-iddata-petf-breeddata-petf-animaldata-petf-age+8 more<div class="petfinder-listing-container" data-petf-api-key=<div class="petfinder-powered-by">Powered by <a href="https://www.petfinder.com" target="_blank">Petfinder</a></div>