Sedox Performance Vehicle Catalogue Security & Risk Analysis

wordpress.org/plugins/sedox-performance-vehicle-catalogue

This plugin allows you to include Sedox Performance Vehicle Catalogue directly into your Wordpress website. The purchase of the Vehicle Catalogue API …

40 active installs v1.5.1-build.1 PHP 7.2+ WP 5.1+ Updated May 16, 2024
chiptuningecu-remapssedox-performancevehicle-catalogue
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Sedox Performance Vehicle Catalogue Safe to Use in 2026?

Generally Safe

Score 92/100

Sedox Performance Vehicle Catalogue has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The sedox-performance-vehicle-catalogue plugin, version 1.5.1-build.1, presents a mixed security posture. While it demonstrates good practices in database querying by exclusively using prepared statements and has no recorded vulnerability history, significant concerns arise from its attack surface and code signals. The presence of four unprotected AJAX handlers and a lack of nonce and capability checks across its entry points expose it to potential unauthorized actions and privilege escalation vulnerabilities. Furthermore, the use of the 'exec' function, even if not directly evidenced in taint analysis, is a critical security risk that could lead to arbitrary code execution if exploited. The taint analysis, while limited to one flow, did identify an unsanitized path, indicating a potential for localized vulnerabilities.

Despite the absence of known CVEs and the solid approach to SQL, the large number of unprotected entry points, particularly AJAX handlers, coupled with the dangerous `exec` function and the identified unsanitized path, create a substantial risk. The plugin's history of no vulnerabilities is a positive indicator, but it cannot mitigate the current findings of insecure coding practices. The overall risk is elevated due to the combination of a broad attack surface without proper authorization and the presence of high-risk functions and code patterns. It is recommended to immediately address the identified security weaknesses.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
  • Missing capability checks
  • Dangerous function 'exec' used
  • Unsanitized path in taint flow
  • Low output escaping percentage
Vulnerabilities
None known

Sedox Performance Vehicle Catalogue Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sedox Performance Vehicle Catalogue Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
6 prepared
Unescaped Output
97
31 escaped
Nonce Checks
0
Capability Checks
0
File Operations
26
External Requests
7
Bundled Libraries
1

Dangerous Functions Found

execexec (vendor_mozart\Analog\Handler\Apprise.php:31

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared6 total queries

Output Escaping

24% escaped128 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<DataController> (src\Controllers\DataController.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Sedox Performance Vehicle Catalogue Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

authwp_ajax_sedox_apisrc\Init.php:34
noprivwp_ajax_sedox_apisrc\Init.php:35
authwp_ajax_logo_get_imagesrc\Init.php:36
authwp_ajax_clear_cachesrc\Init.php:37

Shortcodes 1

[sedox-catalogue] src\Init.php:33
WordPress Hooks 6
actionadmin_menusrc\Api\SettingsApi.php:20
actionadmin_initsrc\Api\SettingsApi.php:24
actionadmin_enqueue_scriptssrc\Base\Enqueue.php:11
actionwp_enqueue_scriptssrc\Base\Enqueue.php:12
actionplugins_loadedsrc\Base\Translations.php:21
filterwp_mail_content_typevendor_mozart\Analog\Handler\WPMail.php:37
Maintenance & Trust

Sedox Performance Vehicle Catalogue Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 16, 2024
PHP min version7.2
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Alternatives

Sedox Performance Vehicle Catalogue Alternatives

No alternatives data available yet.

Developer Profile

Sedox Performance Vehicle Catalogue Developer Profile

Sedox Performance

1 plugin · 40 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sedox Performance Vehicle Catalogue

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/sedox_catalog_css_admin.css/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/js/sedox_catalog_js_admin.js/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/sedox_catalog_css_front.css/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/Chartjs/Chart.min.js/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/Chartjs/Chart.min.css/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/js/sedox_catalog_js_front.js
Script Paths
https://use.typekit.net/kck4ntk.csshttps://fonts.googleapis.com/css?family=Oswald:300,400,500,600,700&display=swap&subset=cyrillic,cyrillic-ext,latin-ext/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/sedox_catalog_css_admin.css/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/js/sedox_catalog_js_admin.js/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/sedox_catalog_css_front.css/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/Chartjs/Chart.min.js+2 more

HTML / DOM Fingerprints

Data Attributes
data-main-menu-slug="sedox_vehicle_catalogue"data-text-domain="sedox-catalogue"
JS Globals
const sc_ajax = var sedox_vehicle_catalogue_vars =
REST Endpoints
/wp-json/sedox-catalogue/v1/admin/data
Shortcode Output
[sedox_vehicle_catalogue_display]
FAQ

Frequently Asked Questions about Sedox Performance Vehicle Catalogue