
WPDevHub Recipe Catalog Security & Risk Analysis
wordpress.org/plugins/wpdevhub-recipesHost Recipes on your WordPress Website
Is WPDevHub Recipe Catalog Safe to Use in 2026?
Generally Safe
Score 85/100WPDevHub Recipe Catalog has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wpdevhub-recipes' plugin v2.7 exhibits a generally good security posture with no known vulnerabilities and a strong emphasis on secure coding practices like prepared statements for all SQL queries and the presence of nonce and capability checks. The static analysis also reveals a very small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not properly authenticated or authorized.
However, there are a few concerning signals. The presence of the `unserialize` function, combined with a taint flow identified as having an unsanitized path, indicates a potential risk. If this `unserialize` function is used with user-supplied data, it could lead to remote code execution vulnerabilities. The low percentage of properly escaped output (18%) also suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, although the attack surface is minimal.
Given the lack of historical vulnerabilities, it's possible these risks are mitigated by other factors not immediately apparent in the provided data, or that the identified taint flow has been handled internally. Nevertheless, the `unserialize` function and the poor output escaping are definite areas requiring attention to ensure a robust security profile.
Key Concerns
- Presence of unserialize function
- Taint flow with unsanitized path
- Low percentage of properly escaped output
WPDevHub Recipe Catalog Security Vulnerabilities
WPDevHub Recipe Catalog Release Timeline
WPDevHub Recipe Catalog Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WPDevHub Recipe Catalog Attack Surface
WordPress Hooks 15
Maintenance & Trust
WPDevHub Recipe Catalog Maintenance & Trust
Maintenance Signals
Community Trust
WPDevHub Recipe Catalog Alternatives
No alternatives data available yet.
WPDevHub Recipe Catalog Developer Profile
9 plugins · 80 total installs
How We Detect WPDevHub Recipe Catalog
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpdevhub-recipes/css/wpdevhub-drc.cssHTML / DOM Fingerprints
wpdevhub-drc-recipe-single<!-- WPDevHub DRC START: Recipes --><!-- WPDevHub DRC END: Recipes -->data-recipe-idWPDEVHUB_DRC_extra_vars[wpdevhub_drc_display_recipe[wpdevhub_drc_display_category