Wijntransport Security & Risk Analysis

wordpress.org/plugins/wijntransport

Host a catalog of wijntransport.com products on your own website.

20 active installs v1.4.1 PHP + WP 4.9+ Updated Apr 12, 2021
wijntransportwinewine-listingwines
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wijntransport Safe to Use in 2026?

Generally Safe

Score 85/100

Wijntransport has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The wijntransport v1.4.1 plugin exhibits a mixed security posture. On the positive side, it has a clean vulnerability history with no known CVEs, and its code analysis reveals no dangerous functions, no direct SQL queries without prepared statements, and a reasonable rate of output escaping. Furthermore, it demonstrates good practices by performing capability checks for its entry points and not bundling external libraries.

However, significant concerns arise from its attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This is a critical weakness as it allows any unauthenticated user to potentially trigger these handlers. While taint analysis shows no immediate issues, the presence of unprotected AJAX endpoints provides a direct pathway for attackers to interact with the plugin's functionality without verification, potentially leading to further exploitation if other vulnerabilities exist within those handlers. The absence of documented vulnerabilities in its history could indicate either a very secure plugin or simply a lack of focused security auditing and discovery.

In conclusion, while the plugin shows strengths in its database interactions and output handling, the two unprotected AJAX endpoints represent a significant, immediately exploitable security risk. This lack of access control on key entry points necessitates immediate attention to mitigate the potential for abuse.

Key Concerns

  • Unprotected AJAX handlers
  • Large attack surface without auth
  • Output escaping at 86%
Vulnerabilities
None known

Wijntransport Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wijntransport Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
152 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

86% escaped176 total outputs
Attack Surface
2 unprotected

Wijntransport Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_wijntransport_block_productincludes\class-wijntransport.php:176
authwp_ajax_wijntransport_unblock_productincludes\class-wijntransport.php:177
WordPress Hooks 14
filterget_canonical_urlincludes\class-wijntransport-api.php:283
actionwp_headincludes\class-wijntransport-api.php:306
actionplugins_loadedincludes\class-wijntransport.php:154
actionadmin_initincludes\class-wijntransport.php:167
actionadmin_enqueue_scriptsincludes\class-wijntransport.php:168
actionadmin_enqueue_scriptsincludes\class-wijntransport.php:169
actionadmin_menuincludes\class-wijntransport.php:170
filtertheme_page_templatesincludes\class-wijntransport.php:171
filterpage_templateincludes\class-wijntransport.php:172
actionwp_enqueue_scriptsincludes\class-wijntransport.php:190
actionwp_enqueue_scriptsincludes\class-wijntransport.php:191
actioninitincludes\class-wijntransport.php:192
filterwpseo_sitemap_indexincludes\class-wijntransport.php:196
actioninitincludes\class-wijntransport.php:197
Maintenance & Trust

Wijntransport Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedApr 12, 2021
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Wijntransport Developer Profile

wijntransport

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wijntransport

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wijntransport/admin/assets/css/mds-admin.min.css/wp-content/plugins/wijntransport/admin/assets/js/mds-admin.min.js
Script Paths
/wp-content/plugins/wijntransport/admin/assets/js/mds-admin.min.js
Version Parameters
wijntransport?ver=mds-admin.min.css?ver=mds-admin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wt-wine-listing-filterwt-wine-listing-search
Data Attributes
data-wine-id
JS Globals
wijntransport_ajax_object
Shortcode Output
[wijntransport_wine_listing]
FAQ

Frequently Asked Questions about Wijntransport