
Plutus Recipe Pro Security & Risk Analysis
wordpress.org/plugins/plutus-recipe-proPlutus Recipe Pro plugin is a user friendly plugin for adding recipes to any of your posts and pages. Beautiful SEO friendly recipes, print versions, …
Is Plutus Recipe Pro Safe to Use in 2026?
Generally Safe
Score 85/100Plutus Recipe Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "plutus-recipe-pro" v1.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are strong indicators of secure coding practices. The taint analysis showing zero flows with unsanitized paths further reinforces this. However, there are areas for concern. The 77% output escaping rate, while not critically low, means that approximately 23% of outputs are not properly escaped, posing a potential risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in those unescaped outputs. Additionally, the plugin lacks nonce checks entirely, which is a critical security measure for protecting against cross-site request forgery (CSRF) attacks on its entry points, particularly the two shortcodes. The complete absence of recorded vulnerabilities is a positive historical signal, suggesting the developers have a good track record or the plugin has not been extensively targeted, but this should not be a substitute for robust security measures in the current version. In conclusion, while the plugin demonstrates a good foundation of secure coding, the unescaped outputs and missing nonce checks represent significant security weaknesses that require attention.
Key Concerns
- Missing nonce checks on entry points
- Unescaped output (approx. 23%)
Plutus Recipe Pro Security Vulnerabilities
Plutus Recipe Pro Code Analysis
Output Escaping
Plutus Recipe Pro Attack Surface
Shortcodes 2
WordPress Hooks 31
Maintenance & Trust
Plutus Recipe Pro Maintenance & Trust
Maintenance Signals
Community Trust
Plutus Recipe Pro Alternatives
Shop Ingredients Button
santa-cruz-savory
The plugin places a small button on each recipe page that allows readers to easily purchase the listed ingredients at a local grocery store.
WP Recipe Maker
wp-recipe-maker
The easy and user-friendly recipe plugin for everyone. Automatic JSON-LD metadata for food AND how-to recipes will improve your SEO!
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)
delicious-recipes
WP Delicious is an SEO-optimized and Schema-friendly recipe plugin for food bloggers to create and display unlimited recipes.
Cooked – Recipe Management
cooked
Cooked is the absolute best way to create & display recipes with WordPress. SEO optimized, galleries, timers, and much more.
Delisho – Recipe Widgets and Blocks
dr-widgets-blocks
Delisho includes 12+ Elementor Widgets and 4 Gutenberg blocks for WP Delicious plugin to create a beautiful and SEO-friendly food blog.
Plutus Recipe Pro Developer Profile
1 plugin · 0 total installs
How We Detect Plutus Recipe Pro
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plutus-recipe-pro/css/magnific-popup.css/wp-content/plugins/plutus-recipe-pro/css/owl.carousel.css/wp-content/plugins/plutus-recipe-pro/css/plutus-recipe-pro.css/wp-content/plugins/plutus-recipe-pro/css/twentysixteen.css/wp-content/plugins/plutus-recipe-pro/css/twentyseventeen.css/wp-content/plugins/plutus-recipe-pro/js/jquery.zoom.min.js/wp-content/plugins/plutus-recipe-pro/js/jquery.magnific-popup.min.js/wp-content/plugins/plutus-recipe-pro/js/owl.carousel.min.js+2 more/wp-content/plugins/plutus-recipe-pro/js/script.jsplutus-recipe-pro/css/plutus-recipe-pro.css?ver=plutus-recipe-pro/css/twentysixteen.css?ver=plutus-recipe-pro/css/twentyseventeen.css?ver=plutus-recipe-pro/js/script.js?ver=HTML / DOM Fingerprints
plutus-recipe-proplutus-recipe-twentysixteenplutus-recipe-twentyseventeendata-noncedata-ajaxUrlPlutusObj