WP Obituary Manager Security & Risk Analysis

wordpress.org/plugins/wp-obituary

WP Obituary Manager is a free WordPress plugin that helps funeral homes, crematories, and cemeteries manage and display obituaries online.

80 active installs v2.0.7 PHP 8.1+ WP 6.7.2+ Updated Sep 23, 2025
memorialobituariesobituaryobituary-managertribute
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Obituary Manager Safe to Use in 2026?

Generally Safe

Score 100/100

WP Obituary Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The wp-obituary plugin v2.0.7 exhibits a generally good security posture with several positive indicators. The absence of known CVEs, zero unpatched vulnerabilities, and the fact that all SQL queries utilize prepared statements are strong points. Additionally, the plugin implements nonce and capability checks on its identified entry points, which is a crucial security measure. The limited attack surface, consisting solely of shortcodes and no unprotected AJAX or REST API endpoints, further contributes to its security. However, there are areas for improvement. The presence of the "unserialize" function is a significant concern as it can lead to Remote Code Execution (RCE) if not handled with extreme caution and proper input sanitization. The low percentage of properly escaped output also suggests a potential risk of Cross-Site Scripting (XSS) vulnerabilities, especially if the serialized data or shortcode inputs are not adequately sanitized before being displayed.

Key Concerns

  • Dangerous function unserialize used
  • Low percentage of properly escaped output
Vulnerabilities
None known

WP Obituary Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Obituary Manager Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
19
7 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$wpffo_data = unserialize( base64_decode($fixed_serialized_data ));includes\functions.php:130
unserialize$wpffo_data= unserialize( base64_decode($fixed_serialized_data) );includes\functions.php:494

Output Escaping

27% escaped26 total outputs
Attack Surface

WP Obituary Manager Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[obit_date_range] includes\functions.php:668
[condolence_count] includes\functions.php:678
[post_published] includes\functions.php:683
WordPress Hooks 27
actioninitadmin\classes\class-obituary.php:21
actionadd_meta_boxesadmin\classes\class-obituary.php:23
actionsave_postadmin\classes\class-obituary.php:25
actionadmin_enqueue_scriptsadmin\classes\class-scripts.php:21
actionadmin_enqueue_scriptsadmin\classes\class-scripts.php:23
actionadmin_menuadmin\classes\class-settings.php:21
actionadmin_initadmin\classes\class-settings.php:23
actionwidgets_initadmin\includes\functions.php:25
actionwidgets_initadmin\includes\functions.php:49
actionobituary_cat_add_form_fieldsadmin\includes\functions.php:75
actioncreated_obituary_catadmin\includes\functions.php:119
actionobituary_cat_edit_form_fieldsadmin\includes\functions.php:135
actionedited_obituary_catadmin\includes\functions.php:187
actionwp_enqueue_scriptsclasses\class-scripts.php:23
filterbody_classincludes\functions.php:54
actionadd_meta_boxesincludes\functions.php:99
actionadd_meta_boxesincludes\functions.php:323
actionsave_postincludes\functions.php:409
actionwp_enqueue_scriptsincludes\functions.php:411
actionadmin_initincludes\functions.php:435
actionwp_obituary_single_after_contentincludes\functions.php:568
filterget_the_archive_titleincludes\functions.php:593
filtercomment_form_defaultsincludes\functions.php:596
filterget_the_archive_descriptionincludes\functions.php:598
filtergettextincludes\functions.php:620
actionplugins_loadedwp-obituary.php:47
filtertemplate_includewp-obituary.php:49
Maintenance & Trust

WP Obituary Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 23, 2025
PHP min version8.1
Downloads5K

Community Trust

Rating46/100
Number of ratings3
Active installs80
Developer Profile

WP Obituary Manager Developer Profile

Arni Cinco

3 plugins · 10K total installs

54
trust score
Avg Security Score
64/100
Avg Patch Time
659 days
View full developer profile
Detection Fingerprints

How We Detect WP Obituary Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-obituary/admin/assets/css/wp-obituary-styles.css/wp-content/plugins/wp-obituary/admin/assets/js/wp-obituary-settings-script.js/wp-content/plugins/wp-obituary/admin/assets/js/wp-obituary-admin-script.js/wp-content/plugins/wp-obituary/assets/css/wp-obituary-styles.css
Script Paths
/wp-content/plugins/wp-obituary/admin/assets/js/wp-obituary-settings-script.js/wp-content/plugins/wp-obituary/admin/assets/js/wp-obituary-admin-script.js
Version Parameters
wp-obituary/admin/assets/css/wp-obituary-styles.css?ver=wp-obituary/admin/assets/js/wp-obituary-settings-script.js?ver=wp-obituary/admin/assets/js/wp-obituary-admin-script.js?ver=wp-obituary/assets/css/wp-obituary-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
obituary
Data Attributes
data-repeater-listdata-repeater-item
FAQ

Frequently Asked Questions about WP Obituary Manager