
Quotepro Office Widget Security & Risk Analysis
wordpress.org/plugins/quotepro-office-widgetAdds the ability to locate offices directly from your wordpress site
Is Quotepro Office Widget Safe to Use in 2026?
Generally Safe
Score 85/100Quotepro Office Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "quotepro-office-widget" v2.0.0 plugin exhibits a mixed security posture. On one hand, the static analysis reveals a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authentication or permission checks. Furthermore, all SQL queries are performed using prepared statements, and there are no file operations or external HTTP requests, which are positive indicators of secure coding practices in those areas. The absence of known vulnerabilities in its history is also a strong point, suggesting a history of stable and potentially well-maintained code.
However, significant concerns arise from the code signals. The presence of the `create_function` is a critical red flag, as it can lead to arbitrary code execution if used with unsanitized input. Additionally, a complete lack of output escaping on all 12 identified output points is a major security weakness, opening the door to Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks further exacerbates these risks, especially if any of the identified output points are reachable through user-supplied input, even if the attack surface appears limited in traditional entry points.
In conclusion, while the plugin boasts a clean vulnerability history and a seemingly small attack surface, the identified code-level weaknesses, particularly the use of `create_function` and the pervasive lack of output escaping, introduce substantial security risks. These issues need immediate attention to mitigate potential XSS and arbitrary code execution vulnerabilities, despite the plugin's strengths in other security aspects.
Key Concerns
- Unescaped output detected
- Dangerous function 'create_function' detected
- Missing nonce checks
- Missing capability checks
Quotepro Office Widget Security Vulnerabilities
Quotepro Office Widget Release Timeline
Quotepro Office Widget Code Analysis
Dangerous Functions Found
Output Escaping
Quotepro Office Widget Attack Surface
WordPress Hooks 9
Maintenance & Trust
Quotepro Office Widget Maintenance & Trust
Maintenance Signals
Community Trust
Quotepro Office Widget Alternatives
Quotepro Insurance Widget
quotepro-insurance-widget
Adds the ability to provide your customers with realtime comparison insurance quotes directly from your wordpress site
Quotepro Payment Widget
quotepro-payment-widget
Adds the ability to accept monthy insurance, loan, rent or utility payments directly from your wordpress site
Office Hours
office-hours
Work Schedule - Time Table.
Ticketsolve Shows
upcoming-ticketsolve-shows
Loads future shows from your Ticketsolve box office server.
XTCZ Top Box Office
xtcz-top-box-office
Real time Weekend Box Office results on your blog.
Quotepro Office Widget Developer Profile
3 plugins · 40 total installs
How We Detect Quotepro Office Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quotepro-office-widget/css/admin.css/wp-content/plugins/quotepro-office-widget/js/admin.js/wp-content/plugins/quotepro-office-widget/css/colorbox.css/wp-content/plugins/quotepro-office-widget/css/widget.csshttps://cdnjs.cloudflare.com/ajax/libs/jquery.maskedinput/1.4.1/jquery.maskedinput.min.jsquotepro-office-widget-admin-styles?ver=quotepro-office-widget-admin-script?ver=quotepro-office-widget-colorbox-styles?ver=quotepro-office-widget-widget-styles?ver=HTML / DOM Fingerprints
quotepro-office-widget-classjQuery.fn.maskedinput