Shop Ingredients Button Security & Risk Analysis

wordpress.org/plugins/santa-cruz-savory

The plugin places a small button on each recipe page that allows readers to easily purchase the listed ingredients at a local grocery store.

10 active installs v0.5.1 PHP 5.4+ WP 4.4+ Updated Feb 18, 2023
cookingfoodingredientsreciperecipes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shop Ingredients Button Safe to Use in 2026?

Generally Safe

Score 85/100

Shop Ingredients Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "santa-cruz-savory" plugin v0.5.1 demonstrates an exceptionally clean static analysis profile, with no identified attack surface elements like AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or capability checks. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and taint flows with unsanitized paths indicates a strong commitment to secure coding practices in these areas. The plugin also exclusively utilizes prepared statements for its SQL queries, a significant security strength.

However, a critical weakness is identified in the output escaping. With 100% of outputs not being properly escaped, there is a high risk of cross-site scripting (XSS) vulnerabilities. Any dynamic content displayed by the plugin to users could potentially be manipulated by an attacker to inject malicious scripts. While the plugin has no recorded vulnerability history, this is not a guarantee of future security and the identified output escaping issue presents a clear and present danger.

In conclusion, "santa-cruz-savory" v0.5.1 excels in avoiding common entry points and secure data handling (SQL). The complete lack of recorded vulnerabilities is a positive indicator, but it is overshadowed by the severe oversight in output escaping. Addressing the XSS risk by implementing proper output escaping should be the immediate priority.

Key Concerns

  • Unescaped output across all outputs
Vulnerabilities
None known

Shop Ingredients Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Shop Ingredients Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Shop Ingredients Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_enqueue_scriptssantaCruzSavoryPlugin.php:45
actionadmin_initsantaCruzSavoryPlugin.php:90
actionadmin_menusantaCruzSavoryPlugin.php:104
Maintenance & Trust

Shop Ingredients Button Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedFeb 18, 2023
PHP min version5.4
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Shop Ingredients Button Developer Profile

santacruzsavory

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shop Ingredients Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://assets.santacruzsavory.com/style.csshttps://assets.santacruzsavory.com/script.js

HTML / DOM Fingerprints

Data Attributes
santacruzsavory_color_schemesantacruzsavory_font_familysantacruzsavory_instacart_affiliate_id
JS Globals
scsParams
FAQ

Frequently Asked Questions about Shop Ingredients Button