
Sedox Performance Vehicle Catalogue Security & Risk Analysis
wordpress.org/plugins/sedox-performance-vehicle-catalogueThis plugin allows you to include Sedox Performance Vehicle Catalogue directly into your Wordpress website. The purchase of the Vehicle Catalogue API …
Is Sedox Performance Vehicle Catalogue Safe to Use in 2026?
Generally Safe
Score 92/100Sedox Performance Vehicle Catalogue has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sedox-performance-vehicle-catalogue plugin, version 1.5.1-build.1, presents a mixed security posture. While it demonstrates good practices in database querying by exclusively using prepared statements and has no recorded vulnerability history, significant concerns arise from its attack surface and code signals. The presence of four unprotected AJAX handlers and a lack of nonce and capability checks across its entry points expose it to potential unauthorized actions and privilege escalation vulnerabilities. Furthermore, the use of the 'exec' function, even if not directly evidenced in taint analysis, is a critical security risk that could lead to arbitrary code execution if exploited. The taint analysis, while limited to one flow, did identify an unsanitized path, indicating a potential for localized vulnerabilities.
Despite the absence of known CVEs and the solid approach to SQL, the large number of unprotected entry points, particularly AJAX handlers, coupled with the dangerous `exec` function and the identified unsanitized path, create a substantial risk. The plugin's history of no vulnerabilities is a positive indicator, but it cannot mitigate the current findings of insecure coding practices. The overall risk is elevated due to the combination of a broad attack surface without proper authorization and the presence of high-risk functions and code patterns. It is recommended to immediately address the identified security weaknesses.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX
- Missing capability checks
- Dangerous function 'exec' used
- Unsanitized path in taint flow
- Low output escaping percentage
Sedox Performance Vehicle Catalogue Security Vulnerabilities
Sedox Performance Vehicle Catalogue Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Sedox Performance Vehicle Catalogue Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Sedox Performance Vehicle Catalogue Maintenance & Trust
Maintenance Signals
Community Trust
Sedox Performance Vehicle Catalogue Alternatives
No alternatives data available yet.
Sedox Performance Vehicle Catalogue Developer Profile
1 plugin · 40 total installs
How We Detect Sedox Performance Vehicle Catalogue
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/sedox_catalog_css_admin.css/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/js/sedox_catalog_js_admin.js/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/sedox_catalog_css_front.css/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/Chartjs/Chart.min.js/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/Chartjs/Chart.min.css/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/js/sedox_catalog_js_front.jshttps://use.typekit.net/kck4ntk.csshttps://fonts.googleapis.com/css?family=Oswald:300,400,500,600,700&display=swap&subset=cyrillic,cyrillic-ext,latin-ext/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/sedox_catalog_css_admin.css/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/js/sedox_catalog_js_admin.js/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/sedox_catalog_css_front.css/wp-content/plugins/sedox-performance-vehicle-catalogue/assets/Chartjs/Chart.min.js+2 moreHTML / DOM Fingerprints
data-main-menu-slug="sedox_vehicle_catalogue"data-text-domain="sedox-catalogue"const sc_ajax = var sedox_vehicle_catalogue_vars = /wp-json/sedox-catalogue/v1/admin/data[sedox_vehicle_catalogue_display]