Store Locator Plus® | Extenders Security & Risk Analysis

wordpress.org/plugins/slp-extenders

Adds power user features like managing location based events, social media information and locations managed by other logged in users to Store Locator …

0 active installs v6.1.1 PHP + WP 6.0+ Updated Dec 29, 2022
eventsextenderssocial-mediauser-managed-locations
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Store Locator Plus® | Extenders Safe to Use in 2026?

Generally Safe

Score 85/100

Store Locator Plus® | Extenders has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "slp-extenders" v6.1.1 exhibits a generally strong security posture with a clean vulnerability history and a high percentage of properly escaped outputs and prepared SQL statements. The absence of known CVEs and a lack of recorded past vulnerabilities are positive indicators. However, the static analysis reveals a few areas for concern. The presence of the deprecated `create_function` is a notable risk, as it can lead to security vulnerabilities if used with user-supplied input, although the taint analysis did not identify any critical or high severity flows related to this. Additionally, the complete lack of nonce checks is a significant weakness. While there are no directly exploitable entry points detected (like AJAX handlers or REST API routes without authentication), the absence of nonce verification means that even if such entry points were added in the future without proper authentication checks, they would be vulnerable to Cross-Site Request Forgery (CSRF) attacks. The bundled Freemius library at v1.0 may also be outdated, which could present its own set of risks if it contains known vulnerabilities.

Overall, the plugin's current state appears relatively secure due to its limited attack surface and good output sanitization practices. The main identified risks stem from the use of a deprecated function and the complete absence of nonce checks, which indicates a lack of defense-in-depth against potential CSRF attacks. The vulnerability history is a significant strength, suggesting a commitment to security or simply a lack of exposure. However, relying solely on the absence of past vulnerabilities can be misleading, and proactive security measures like proper nonce implementation should be prioritized to strengthen its resilience against future threats.

Key Concerns

  • Dangerous functions: create_function used
  • Nonce checks: 0 detected
  • Bundled libraries: Freemius v1.0 potentially outdated
Vulnerabilities
None known

Store Locator Plus® | Extenders Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Store Locator Plus® | Extenders Code Analysis

Dangerous Functions
2
Raw SQL Queries
1
2 prepared
Unescaped Output
1
31 escaped
Nonce Checks
0
Capability Checks
5
File Operations
1
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

create_functioncreate_function(include\base\loader.php:13
create_functioncreate_function(include\base\loader.php:34

Bundled Libraries

Freemius1.0

SQL Query Safety

67% prepared3 total queries

Output Escaping

97% escaped32 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
display (include\module\adminui\SLP_Extenders_AdminUI_UserManager_Table.php:247)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Store Locator Plus® | Extenders Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 32
actionadmin_noticesinclude\base\loader.php:11
actionadmin_noticesinclude\base\loader.php:32
actionadmin_enqueue_scriptsinclude\module\admin\SLP_Extenders_Admin.php:93
filterslp_locations_manage_bulkactionsinclude\module\admin\SLP_Extenders_Admin_User_Managed.php:51
actionslp_manage_locations_actioninclude\module\admin\SLP_Extenders_Admin_User_Managed.php:56
actionslp_manage_location_whereinclude\module\admin\SLP_Extenders_Admin_User_Managed.php:60
actionslp_location_addedinclude\module\admin\SLP_Extenders_Admin_User_Managed.php:67
actionslp_location_savedinclude\module\admin\SLP_Extenders_Admin_User_Managed.php:68
actionslp_deletelocation_startinginclude\module\admin\SLP_Extenders_Admin_User_Managed.php:69
filterslp_manage_location_columnsinclude\module\admin\SLP_Extenders_Admin_User_Managed.php:79
filterslp_column_datainclude\module\admin\SLP_Extenders_Admin_User_Managed.php:81
filterslp_edit_location_change_extended_data_infoinclude\module\admin\SLP_Extenders_Admin_User_Managed.php:82
actionuser_registerinclude\module\admin\SLP_Extenders_Admin_User_Managed.php:91
filteruser_row_actionsinclude\module\admin\SLP_Extenders_Admin_User_Managed.php:93
filterbulk_actions-usersinclude\module\admin\SLP_Extenders_Admin_User_Managed.php:94
filtermanage_users_columnsinclude\module\admin\SLP_Extenders_Admin_User_Managed.php:96
actionmanage_users_custom_columninclude\module\admin\SLP_Extenders_Admin_User_Managed.php:97
filterslp_results_marker_datainclude\module\ajax\SLP_Extenders_AJAX_User_Managed.php:42
filterslp_get_text_stringinclude\module\text\SLP_Extenders_Text.php:17
filterwp_print_stylesinclude\module\user\SLP_Extenders_User_Managed.php:31
actionshow_user_profileinclude\module\user\SLP_Extenders_User_Managed.php:34
actionedit_user_profileinclude\module\user\SLP_Extenders_User_Managed.php:35
filterconnect_urlslp-extenders.php:114
filterafter_skip_urlslp-extenders.php:115
filterafter_connect_urlslp-extenders.php:116
filterafter_pending_connect_urlslp-extenders.php:117
actionplugins_loadedslp-extenders.php:144
actionadmin_initslp-extenders.php:296
actionadmin_menuslp-extenders.php:297
actionuser_admin_menuslp-extenders.php:299
filterslp_get_addonslp-extenders.php:302
actiondmp_addpanelslp-extenders.php:308
Maintenance & Trust

Store Locator Plus® | Extenders Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 29, 2022
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Store Locator Plus® | Extenders Developer Profile

DeBAAT

7 plugins · 6K total installs

90
trust score
Avg Security Score
86/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Store Locator Plus® | Extenders

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/slp-extenders/include/css/styles.css/wp-content/plugins/slp-extenders/include/js/slp-extenders-admin.js/wp-content/plugins/slp-extenders/include/js/slp-extenders-frontend.js
Script Paths
/wp-content/plugins/slp-extenders/include/js/slp-extenders-admin.js/wp-content/plugins/slp-extenders/include/js/slp-extenders-frontend.js
Version Parameters
slp-extenders/include/css/styles.css?ver=slp-extenders/include/js/slp-extenders-admin.js?ver=slp-extenders/include/js/slp-extenders-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
slp-extenders-admin-wrap
HTML Comments
DO NOT REMOVE THIS IF, IT IS ESSENTIAL FOR THE `function_exists` CALL ABOVE TO PROPERLY WORK.
Data Attributes
data-slp-ext-setting
JS Globals
SLP_Extenders_Settings
FAQ

Frequently Asked Questions about Store Locator Plus® | Extenders