
Shop Ingredients Button Security & Risk Analysis
wordpress.org/plugins/santa-cruz-savoryThe plugin places a small button on each recipe page that allows readers to easily purchase the listed ingredients at a local grocery store.
Is Shop Ingredients Button Safe to Use in 2026?
Generally Safe
Score 85/100Shop Ingredients Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "santa-cruz-savory" plugin v0.5.1 demonstrates an exceptionally clean static analysis profile, with no identified attack surface elements like AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or capability checks. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and taint flows with unsanitized paths indicates a strong commitment to secure coding practices in these areas. The plugin also exclusively utilizes prepared statements for its SQL queries, a significant security strength.
However, a critical weakness is identified in the output escaping. With 100% of outputs not being properly escaped, there is a high risk of cross-site scripting (XSS) vulnerabilities. Any dynamic content displayed by the plugin to users could potentially be manipulated by an attacker to inject malicious scripts. While the plugin has no recorded vulnerability history, this is not a guarantee of future security and the identified output escaping issue presents a clear and present danger.
In conclusion, "santa-cruz-savory" v0.5.1 excels in avoiding common entry points and secure data handling (SQL). The complete lack of recorded vulnerabilities is a positive indicator, but it is overshadowed by the severe oversight in output escaping. Addressing the XSS risk by implementing proper output escaping should be the immediate priority.
Key Concerns
- Unescaped output across all outputs
Shop Ingredients Button Security Vulnerabilities
Shop Ingredients Button Code Analysis
Output Escaping
Shop Ingredients Button Attack Surface
WordPress Hooks 3
Maintenance & Trust
Shop Ingredients Button Maintenance & Trust
Maintenance Signals
Community Trust
Shop Ingredients Button Alternatives
Plutus Recipe Pro
plutus-recipe-pro
Plutus Recipe Pro plugin is a user friendly plugin for adding recipes to any of your posts and pages. Beautiful SEO friendly recipes, print versions, …
WP Recipe Maker
wp-recipe-maker
The easy and user-friendly recipe plugin for everyone. Automatic JSON-LD metadata for food AND how-to recipes will improve your SEO!
WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)
delicious-recipes
WP Delicious is an SEO-optimized and Schema-friendly recipe plugin for food bloggers to create and display unlimited recipes.
Cooked – Recipe Management
cooked
Cooked is the absolute best way to create & display recipes with WordPress. SEO optimized, galleries, timers, and much more.
Delisho – Recipe Widgets and Blocks
dr-widgets-blocks
Delisho includes 12+ Elementor Widgets and 4 Gutenberg blocks for WP Delicious plugin to create a beautiful and SEO-friendly food blog.
Shop Ingredients Button Developer Profile
1 plugin · 10 total installs
How We Detect Shop Ingredients Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://assets.santacruzsavory.com/style.csshttps://assets.santacruzsavory.com/script.jsHTML / DOM Fingerprints
santacruzsavory_color_schemesantacruzsavory_font_familysantacruzsavory_instacart_affiliate_idscsParams