WPCafe Restaurant Addon for Oxygen Builder Security & Risk Analysis

wordpress.org/plugins/wpcafe-oxygen-addon

WPCafe Oxygen Builder Addons enables the WPCafe Food Menu and Restaurant Reservation plugin to parse WPCafe widgets inside the Oxygen editor for Pages …

10 active installs v1.1.4 PHP 7.2+ WP 6.2+ Updated Nov 30, 2025
buildereditorfood-menuoxygen-builderrestaurant
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPCafe Restaurant Addon for Oxygen Builder Safe to Use in 2026?

Generally Safe

Score 100/100

WPCafe Restaurant Addon for Oxygen Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

Based on the static analysis and vulnerability history, wpcafe-oxygen-addon v1.1.4 exhibits a strong security posture with no immediate critical or high-risk vulnerabilities identified. The plugin demonstrates excellent coding practices by employing prepared statements for all SQL queries and properly escaping a high percentage of its outputs. Furthermore, the absence of external HTTP requests, file operations, and critical taint flows is commendable. The zero-day vulnerability history is a significant strength, suggesting a well-maintained and secure codebase over time.

However, a notable concern arises from the complete lack of nonce checks and capability checks for all identified entry points. While the current static analysis reports zero unprotected entry points, this absence of authentication and authorization mechanisms creates a potential blind spot. Should any new entry points be introduced in future versions, or if existing ones are implicitly assumed to be protected by other means, the plugin would be highly susceptible to various attacks without these fundamental security controls. The lack of analysis in taint flows (0 total flows analyzed) also means that the absence of identified vulnerabilities might be due to the limited scope of the analysis rather than inherent security.

In conclusion, wpcafe-oxygen-addon v1.1.4 is currently in a good security state, characterized by robust data handling and a clean vulnerability record. The primary weakness lies in the reliance on implicit security for its entry points, which is a risky practice. Addressing the lack of explicit nonce and capability checks would significantly enhance its overall security resilience against potential future threats.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • No taint flows analyzed
Vulnerabilities
None known

WPCafe Restaurant Addon for Oxygen Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WPCafe Restaurant Addon for Oxygen Builder Release Timeline

v1.1.4Current
v1.1.3
v1.1.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

WPCafe Restaurant Addon for Oxygen Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
365 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped381 total outputs
Attack Surface

WPCafe Restaurant Addon for Oxygen Builder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitbootstrap.php:26
actionadmin_noticesbootstrap.php:40
actionadmin_noticesbootstrap.php:46
actionoxygen_add_plus_sectionsbootstrap.php:54
actionoxygen_add_plus_wpcafe_section_contentbootstrap.php:58
actionwp_enqueue_scriptscore/enqueue/enqueue.php:18
actionoxygen_enqueue_frontend_scriptscore/enqueue/enqueue.php:19
actioninitwpcafe-oxygen-addon.php:63
actionplugins_loadedwpcafe-oxygen-addon.php:66
Maintenance & Trust

WPCafe Restaurant Addon for Oxygen Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 30, 2025
PHP min version7.2
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WPCafe Restaurant Addon for Oxygen Builder Developer Profile

Arraytics

10 plugins · 20K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
27 days
View full developer profile
Detection Fingerprints

How We Detect WPCafe Restaurant Addon for Oxygen Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpcafe-oxygen-addon/assets/css/wpcafe-oxygen-addon.css/wp-content/plugins/wpcafe-oxygen-addon/assets/js/wpcafe-oxygen-addon.js
Script Paths
/wp-content/plugins/wpcafe-oxygen-addon/assets/js/wpcafe-oxygen-addon.js
Version Parameters
wpcafe-oxygen-addon/assets/css/wpcafe-oxygen-addon.css?ver=wpcafe-oxygen-addon/assets/js/wpcafe-oxygen-addon.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WPCafe Restaurant Addon for Oxygen Builder