
WP Business Directory FREE Security & Risk Analysis
wordpress.org/plugins/wp-business-directory-freeA customisable, easy to use Wordpress Business Directory plug-in for Wordpress. Build and customise your own business directory in no time.
Is WP Business Directory FREE Safe to Use in 2026?
Generally Safe
Score 85/100WP Business Directory FREE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The overall security posture of wp-business-directory-free v1.0.8.2 shows some concerning weaknesses despite a lack of known historical vulnerabilities. The plugin exhibits a significant attack surface with 5 AJAX handlers, all of which lack authentication checks, presenting a clear risk of unauthorized access and execution of potentially sensitive functions. While the majority of SQL queries use prepared statements, the presence of 4 taint flows with unsanitized paths, specifically two of high severity, indicates potential vulnerabilities that could be exploited if user-supplied data is not properly validated and sanitized before being used in file operations or other sensitive contexts.
The absence of any recorded CVEs is a positive sign, suggesting the plugin has historically been developed with some security considerations or has not been a prominent target. However, this should not be relied upon as a sole indicator of current security. The code signals for dangerous functions and external HTTP requests are positive, indicating good practices in those areas. The significant number of output operations (512) with only 57% properly escaped is a moderate concern, potentially leading to cross-site scripting (XSS) vulnerabilities if certain outputs are not correctly handled. The plugin's strengths lie in its use of prepared statements for SQL and the absence of dangerous functions. The primary weaknesses are the unprotected AJAX endpoints and the high-severity taint flows.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows
- Unescaped output
WP Business Directory FREE Security Vulnerabilities
WP Business Directory FREE Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Business Directory FREE Attack Surface
AJAX Handlers 5
Shortcodes 3
WordPress Hooks 6
Maintenance & Trust
WP Business Directory FREE Maintenance & Trust
Maintenance Signals
Community Trust
WP Business Directory FREE Alternatives
Directorist: AI-Powered Business Directory, Listings & Classified Ads
directorist
Build any type of directory website such as a business directory, job directory, classifieds directory, and more with this WordPress directory plugin.
Business Directory Plugin – Easy Listing Directories for WordPress
business-directory-plugin
The easy Business Directory Plugin for WordPress. Build an easy team directory, member directory, staff directory, church directory, and more.
Classified Listing – AI-Powered Classified ads & Business Directory Plugin
classified-listing
A Classified ads and Business Directory plugin for WordPress, to create classified listing, real estate directory, local business directory, and more.
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
geodirectory
A superb WordPress Business Directory plugin to create a local business directory, classified ads directory, or job listings board.
HivePress – Business Directory & Classified Ads Plugin
hivepress
A simple yet powerful plugin to create a business directory, job board, real estate, classified ads, or basically any type of directory website.
WP Business Directory FREE Developer Profile
3 plugins · 50 total installs
How We Detect WP Business Directory FREE
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-business-directory-free/css/font-awesome.min.css/wp-content/plugins/wp-business-directory-free/js/slideshow.js/wp-content/plugins/wp-business-directory-free/js/fe-business-details.js/wp-content/plugins/wp-business-directory-free/css/slideshow.css/wp-content/plugins/wp-business-directory-free/template/css/wpbdf-business-details-page.css//maps.googleapis.com/maps/api/jswp-business-directory-free/js/slideshow.js?ver=wp-business-directory-free/js/fe-business-details.js?ver=HTML / DOM Fingerprints
wpbdf-paginationwpbdf-business-details-pagedata-wpbdf-idwpbdf_get_google_api_key