ZE To Do List Security & Risk Analysis

wordpress.org/plugins/ze-to-do-list

ZE To Do List.

0 active installs v0.1.0 PHP 7.2+ WP 6.6+ Updated Nov 19, 2024
tasksto-do-listto-dotodotodo-list
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ZE To Do List Safe to Use in 2026?

Generally Safe

Score 92/100

ZE To Do List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'ze-to-do-list' plugin v0.1.0 exhibits a strong security posture based on the provided static analysis. All identified entry points, including AJAX handlers, are protected with nonce checks. The code demonstrates good practice by exclusively using prepared statements for SQL queries and properly escaping all output. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. Furthermore, the plugin has no recorded vulnerability history, indicating a consistent focus on security by its developers or a lack of past exploitation attempts.

Vulnerabilities
None known

ZE To Do List Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ZE To Do List Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
3 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

100% escaped3 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
zetdl_retrieve_to_do (ze-to-do-list.php:90)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ZE To Do List Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_zetdl_retrieve_to_dosze-to-do-list.php:88
authwp_ajax_zetdl_retrieve_to_doze-to-do-list.php:109
authwp_ajax_zetdl_add_to_doze-to-do-list.php:141
authwp_ajax_zetdl_delete_to_doze-to-do-list.php:172
WordPress Hooks 3
actioninitze-to-do-list.php:30
actionwp_enqueue_scriptsze-to-do-list.php:57
actionwp_enqueue_scriptsze-to-do-list.php:69
Maintenance & Trust

ZE To Do List Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 19, 2024
PHP min version7.2
Downloads562

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ZE To Do List Developer Profile

wanzhenen

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZE To Do List

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ze-to-do-list/style.css/wp-content/plugins/ze-to-do-list/script.js
Script Paths
/wp-content/plugins/ze-to-do-list/script.js
Version Parameters
ze-to-do-list/style.css?ver=/script.js?ver=

HTML / DOM Fingerprints

JS Globals
config
REST Endpoints
/wp-json/wp/v2/posts/wp-json/wp/v2/pages/wp-json/wp/v2/media/wp-json/wp/v2/categories/wp-json/wp/v2/tags/wp-json/wp/v2/comments/wp-json/wp/v2/users/wp-json/wp/v2/types/wp-json/wp/v2/taxonomies/wp-json/wp/v2/settings/wp-json/wp/v2/themes/wp-json/wp/v2/plugins/wp-json/wp/v2/blocks/wp-json/wp/v2/search/wp-json/wp/v2/statuses/wp-json/wp/v2/menus/wp-json/wp/v2/menu-locations/wp-json/wp/v2/block-patterns/wp-json/wp/v2/block-renderer/wp-json/wp/v2/themes/site-icons/wp-json/wp/v2/themes/navigation/wp-json/wp/v2/themes/site-title/wp-json/wp/v2/themes/site-tagline/wp-json/wp/v2/themes/custom-logo/wp-json/wp/v2/themes/site-icon/wp-json/wp/v2/themes/site-logo/wp-json/wp/v2/themes/custom-logo-id/wp-json/wp/v2/themes/site-icon-id/wp-json/wp/v2/themes/site-logo-id
FAQ

Frequently Asked Questions about ZE To Do List