
Store Manager Security & Risk Analysis
wordpress.org/plugins/store-managerStore manager with control over opening hours, location, images and much more.
Is Store Manager Safe to Use in 2026?
Generally Safe
Score 85/100Store Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "store-manager" v1.0.2.2 plugin exhibits several concerning security practices, despite a clean vulnerability history. A significant portion of its attack surface, specifically two AJAX handlers, lacks proper authentication checks. This creates direct entry points for attackers to potentially exploit the plugin's functionality without authorization. Furthermore, the plugin relies heavily on direct SQL queries, with none utilizing prepared statements. This is a critical oversight that exposes the application to SQL injection vulnerabilities. The low percentage of properly escaped output (4%) is also a major concern, indicating a high risk of cross-site scripting (XSS) attacks.
The taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high, still represent potential security weaknesses that could be leveraged for unauthorized actions or data manipulation. The absence of any recorded CVEs is positive, but it should not be seen as an indicator of perfect security, especially given the widespread vulnerabilities found in the code analysis.
Overall, the plugin's security posture is weak due to a large number of unprotected entry points, the absence of prepared statements for all SQL queries, and poor output escaping. While the lack of a vulnerability history is a strength, it is overshadowed by the clear and present risks identified in the static analysis. Developers should prioritize addressing the SQL injection and XSS risks, as well as implementing proper authentication and authorization checks on all AJAX endpoints.
Key Concerns
- AJAX handlers without auth checks
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
- Missing nonce checks on AJAX
Store Manager Security Vulnerabilities
Store Manager Release Timeline
Store Manager Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Store Manager Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Store Manager Maintenance & Trust
Maintenance Signals
Community Trust
Store Manager Alternatives
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
GEO my WP
geo-my-wp
Advanced geolocation, mapping, and proximity search plugin. Geotag post types and BuddyPress members, and create advanced proximity search forms.
Locatoraid Store Locator
locatoraid
A lightweight, reliable store locator backed by ongoing maintenance, updates, and support. Premium version adds CSV import, custom fields, custom map …
Store Locator for WordPress📍
storelocator
Create a store locator for your website in minutes. Add all the store locations in google sheets and embed map on your website.
Themify Store Locator
themify-store-locator
A free plugin to add store locations and stores map in your WordPress site.
Store Manager Developer Profile
3 plugins · 40 total installs
How We Detect Store Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/store-manager/css/store-manager.css/wp-content/plugins/store-manager/js/store-manager.js/wp-content/plugins/store-manager/js/store-manager.jsstore-manager/css/store-manager.css?ver=store-manager/js/store-manager.js?ver=HTML / DOM Fingerprints
sm-optionsdata-sm-option-group[store-manager-form]