
Stylish Price List – Price Table Builder & QR Code Restaurant Menu Security & Risk Analysis
wordpress.org/plugins/stylish-price-listStop Losing Customers Due to Confusing Pricing - Transform confused visitors into paying customers with crystal-clear price lists that increase conver …
Is Stylish Price List – Price Table Builder & QR Code Restaurant Menu Safe to Use in 2026?
Generally Safe
Score 89/100Stylish Price List – Price Table Builder & QR Code Restaurant Menu has a strong security track record. Known vulnerabilities have been patched promptly.
The "stylish-price-list" plugin v7.2.5 exhibits a mixed security posture. On the positive side, there are no unprotected entry points found in the static analysis, indicating a good awareness of basic security practices like nonce and capability checks. The plugin also demonstrates a reasonable level of output escaping and uses prepared statements for a majority of its SQL queries. However, the presence of the `unserialize` function is a significant concern, as it can lead to remote code execution if an attacker can control the serialized data. While no critical or high severity taint flows were identified in this specific analysis, the potential for `unserialize` to be exploited remains.
The plugin's vulnerability history is concerning, with a total of 6 known CVEs, including one previously rated as critical. The common vulnerability types of Cross-site Scripting and Missing Authorization, coupled with a critical historical CVE, suggest potential weaknesses in input validation and access control that may not have been fully addressed. The fact that there are currently no unpatched vulnerabilities is a positive sign, but the recurring nature of these vulnerability types indicates an ongoing need for vigilance and robust security practices. The last recorded vulnerability date also suggests a need for regular security audits and updates.
Overall, while the plugin has implemented several good security practices, the presence of `unserialize` and the historical prevalence of XSS and authorization vulnerabilities present tangible risks. The current version appears to have addressed past CVEs, but the underlying patterns in historical vulnerabilities warrant careful consideration. Users should be aware of the potential risks associated with the `unserialize` function and ensure the plugin is kept up-to-date with any future patches.
Key Concerns
- Dangerous function: unserialize found
- Vulnerability history: 1 critical CVE
- Vulnerability history: 5 medium CVEs
- Taint analysis: 5 unsanitized path flows
- SQL queries: 33% not using prepared statements
- Common vulnerability types: XSS & Missing Auth
Stylish Price List – Price Table Builder & QR Code Restaurant Menu Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Stylish Price List <= 7.2.2 - Missing Authorization
Stylish Price List <= 7.1.11 - Authenticated (Admin+) Stored Cross-Site Scripting
Stylish Price List <= 7.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Stylish Price List <= 7.0.17 - Missing Authorization
Stylish Price List <= 6.9.0 - Missing Authorization
Stylish Price List < 6.9.0 - Arbitrary Image Upload
Stylish Price List – Price Table Builder & QR Code Restaurant Menu Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Stylish Price List – Price Table Builder & QR Code Restaurant Menu Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 30
Scheduled Events 2
Maintenance & Trust
Stylish Price List – Price Table Builder & QR Code Restaurant Menu Maintenance & Trust
Maintenance Signals
Community Trust
Stylish Price List – Price Table Builder & QR Code Restaurant Menu Alternatives
RioVizual — Table Blocks for Comparison, Pricing and Pros & Cons
riovizual
Drag and drop Gutenberg table blocks plugin for WordPress block editor to easily create customizable, responsive tables that boost engagement and conv …
TableKit: Table Builder Blocks for Gutenberg
table-builder-block
Powerful table builder block for Gutenberg block editor.
Ninja Tables – Easy Data Table Builder
ninja-tables
Best WordPress table builder plugin packed with versatile features to create fully responsive data tables of any kind.
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin
wpdatatables
The best WordPress table plugin. Create responsive, and searchable tables and charts from Excel (.xlsx, .xls or .ods), CSV, XML, JSON, and PHP.
WP Table Builder – Drag & Drop Table Builder
wp-table-builder
Drag and Drop Table Builder Plugin. Build Responsive Tables Easily.
Stylish Price List – Price Table Builder & QR Code Restaurant Menu Developer Profile
5 plugins · 5K total installs
How We Detect Stylish Price List – Price Table Builder & QR Code Restaurant Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stylish-price-list/assets/css/spl-style.css/wp-content/plugins/stylish-price-list/assets/js/spl-script.js/wp-content/plugins/stylish-price-list/assets/js/spl-gutenberg-block.js/wp-content/plugins/stylish-price-list/assets/js/spl-script.js/wp-content/plugins/stylish-price-list/assets/js/spl-gutenberg-block.jsstylish-price-list/assets/css/spl-style.css?ver=stylish-price-list/assets/js/spl-script.js?ver=stylish-price-list/assets/js/spl-gutenberg-block.js?ver=HTML / DOM Fingerprints
spl-price-list-wrapperspl-list-itemspl-item-titlespl-item-pricespl-item-descriptionspl-list-category-titlespl-category-wrapperspl-search-formCheck SiteOrigin Plugin active or notEnduncomments to turn on php errors logWe are in admin modedata-spl-iddata-spl-optionsspl_params[spl-price-list[spl-pricing-table