
Price List Security & Risk Analysis
wordpress.org/plugins/price-list-emUna breve descripción del plugin.
Is Price List Safe to Use in 2026?
Generally Safe
Score 85/100Price List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "price-list-em" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by generally utilizing prepared statements for SQL queries and properly escaping output. The absence of any recorded vulnerabilities in its history is also a strong indicator of a relatively secure development process. However, the static analysis reveals significant concerns, particularly regarding its attack surface and the handling of user input.
The plugin has an attack surface of three entry points, with one of these being an AJAX handler that lacks authentication checks. This is a critical oversight, as it potentially allows unauthenticated users to trigger actions within the plugin. Furthermore, the taint analysis indicates three high-severity flows with unsanitized paths, suggesting that user-supplied data could be manipulated to achieve unintended and potentially harmful results within the application's logic. The presence of a bundled library (Select2) also warrants attention, as outdated versions could introduce known vulnerabilities.
In conclusion, while the plugin's track record and general coding hygiene for SQL and output are commendable, the identified unprotected AJAX handler and high-severity unsanitized taint flows represent substantial risks that could be exploited. Addressing these specific issues should be the highest priority to improve the plugin's overall security.
Key Concerns
- AJAX handler without authentication check
- High severity taint flow with unsanitized path
- Bundled library (Select2) may be outdated
Price List Security Vulnerabilities
Price List Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Price List Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Price List Maintenance & Trust
Maintenance Signals
Community Trust
Price List Alternatives
Stylish Price List – Price Table Builder & QR Code Restaurant Menu
stylish-price-list
Stop Losing Customers Due to Confusing Pricing - Transform confused visitors into paying customers with crystal-clear price lists that increase conver …
Great Restaurant Menu WP
best-restaurant-menu-by-pricelisto
The fastest and easiest way to create a professional-looking menu or price list for your restaurant or business.
Restaurant Menu – Food Ordering System – Table Reservation
menu-ordering-reservations
Create a restaurant menu and start taking food orders online, with no commissions or costs. Table reservations are also available for free.
Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin
orderable
Take your restaurant/food business online with the online ordering system plugin for WordPress, Orderable.
Five Star Restaurant Menu and Food Ordering
food-and-drink-menu
Restaurant menu and food ordering system that is easy to set up and integrates with any theme. Includes restaurant menu blocks and patterns.
Price List Developer Profile
1 plugin · 0 total installs
How We Detect Price List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/price-list-em/dist/public.css/wp-content/plugins/price-list-em/dist/public.js/wp-content/plugins/price-list-em/dist/libs/bootstrap/bootstrap.min.css/wp-content/plugins/price-list-em/dist/libs/bootstrap/bootstrap.bundle.min.js/wp-content/plugins/price-list-em/dist/libs/select2/select2.min.css/wp-content/plugins/price-list-em/dist/libs/select2/select2.min.js/wp-content/plugins/price-list-em/dist/admin.css/wp-content/plugins/price-list-em/dist/libs/sortable/sortable.js+2 more/wp-content/plugins/price-list-em/dist/public.js/wp-content/plugins/price-list-em/dist/libs/bootstrap/bootstrap.bundle.min.js/wp-content/plugins/price-list-em/dist/libs/select2/select2.min.js/wp-content/plugins/price-list-em/dist/libs/sortable/sortable.js/wp-content/plugins/price-list-em/dist/admin.jsprice-list-em/dist/public.css?ver=price-list-em/dist/public.js?ver=price-list-em/dist/admin.css?ver=price-list-em/dist/libs/sortable/sortable.js?ver=price-list-em/dist/admin.js?ver=HTML / DOM Fingerprints
em-price-list-adem-price-list-publicplem-product-controllerdata1<div id="show_list"></div>