
WP Restaurant Price List Security & Risk Analysis
wordpress.org/plugins/wp-restaurant-price-listShow your price list with the description and cost of the items, divided by categories.
Is WP Restaurant Price List Safe to Use in 2026?
Generally Safe
Score 85/100WP Restaurant Price List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-restaurant-price-list" v1.4.1 plugin exhibits a mixed security posture. On the positive side, it has a very limited attack surface, with only one shortcode and no exposed AJAX handlers or REST API routes that are accessible without authentication or permission checks. The code also demonstrates good practices regarding database interactions, with 100% of SQL queries using prepared statements and no file operations or external HTTP requests detected.
However, a significant concern arises from the complete lack of output escaping. With 35 total outputs analyzed and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered by the plugin, particularly if it originates from user input or other potentially untrusted sources, is vulnerable to malicious injection. The absence of nonce checks and capability checks on its single entry point also means that potentially sensitive actions or data retrieval could be performed without proper authorization or protection against Cross-Site Request Forgery (CSRF).
The plugin's vulnerability history is currently clean, with no recorded CVEs. This, combined with the static analysis findings, suggests that while the plugin has not been historically exploited, the current version contains a critical weakness in its output handling that could be easily exploited. The bundling of the Select2 library also warrants attention for potential versioning issues, although no specific vulnerabilities are listed.
Key Concerns
- 0% output escaping on 35 outputs
- 0 nonce checks on entry points
- 0 capability checks on entry points
- Bundled library (Select2) without version check
WP Restaurant Price List Security Vulnerabilities
WP Restaurant Price List Code Analysis
Bundled Libraries
Output Escaping
WP Restaurant Price List Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
WP Restaurant Price List Maintenance & Trust
Maintenance Signals
Community Trust
WP Restaurant Price List Alternatives
Stylish Price List – Price Table Builder & QR Code Restaurant Menu
stylish-price-list
Stop Losing Customers Due to Confusing Pricing - Transform confused visitors into paying customers with crystal-clear price lists that increase conver …
Great Restaurant Menu WP
best-restaurant-menu-by-pricelisto
The fastest and easiest way to create a professional-looking menu or price list for your restaurant or business.
Price List
price-list-em
Una breve descripción del plugin.
Pricing Table – Responsive & Easy
abc-pricing-table
Display pricing plans with responsive tables. Unlimited packages, 4 templates, shortcode support. Works with Elementor and Gutenberg.
Pricing Table Block – Show Product or Service Pricing in Table Format
b-pricing-table
Create and display a professional-looking product pricing table in WordPress.
WP Restaurant Price List Developer Profile
3 plugins · 2K total installs
How We Detect WP Restaurant Price List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-restaurant-price-list/assets/meta-box/css/custom.css/wp-content/plugins/wp-restaurant-price-list/assets/meta-box/css/custom.min.css/wp-content/plugins/wp-restaurant-price-list/assets/meta-box/js/custom.js/wp-content/plugins/wp-restaurant-price-list/assets/meta-box/js/custom.min.js/wp-content/plugins/wp-restaurant-price-list/admin/css/wp-restaurant-price-list-admin.css/wp-content/plugins/wp-restaurant-price-list/admin/js/wp-restaurant-price-list-admin.js/wp-content/plugins/wp-restaurant-price-list/public/css/wp-restaurant-price-list-public.css/wp-content/plugins/wp-restaurant-price-list/public/js/wp-restaurant-price-list-public.jsplugin_dir_url( __FILE__ ) . 'assets/meta-box/js/custom.js'plugin_dir_url( __FILE__ ) . 'admin/js/wp-restaurant-price-list-admin.js'plugin_dir_url( __FILE__ ) . 'public/js/wp-restaurant-price-list-public.js'wp-restaurant-price-list/admin/css/wp-restaurant-price-list-admin.css?ver=wp-restaurant-price-list/admin/js/wp-restaurant-price-list-admin.js?ver=wp-restaurant-price-list/public/css/wp-restaurant-price-list-public.css?ver=wp-restaurant-price-list/public/js/wp-restaurant-price-list-public.js?ver=HTML / DOM Fingerprints
wprpl_wrapperMetaBoxPlugin Name: WP Restaurant Price Listdata-iddata-titledata-pricewp_restaurant_price_list_object[wp_restaurant_price_list]