WP Directory Kit
by WPDirectoryKit · Uncategorized
Also makes 5 other plugins · 3.4K+ installs across the portfolio →
Build your Directory portal, demos for Real Estate Agency and Car Dealership included
90 health vs 56 average across 16,376 Uncategorized plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,424 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
5.4K
now · peak 9.2K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
14
releases in the last 12 months
2mo ago
latest release · v1.5.3
31
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 62% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “2K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2022-10-04 · 1,421 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from. The recent download trend is too spiky to read.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ gazirizgar8mo ago
It would be perfect if it were improved further
Read on wp.org ↗ - ★★★★★ jorjsarabia241.1y ago
Great services thanks
Read on wp.org ↗ - ★★★★★ mekletterapeitu1.3y ago
Good plugin, decided to use this one instead similar once i was using before because this looks better and have some better functionality. When i got into some issues support was timely, precise and overall helped me with all issues and bugs.
Read on wp.org ↗ - ★★★★★ assassin17171.5y ago
Easy to set up, highly customizable, and perfect for creating professional directories.
Read on wp.org ↗ - ★★★★★ gressi332.0y ago
You are the best! Thanks a lot for your work! This topic was modified 1 year, 9 months ago by gressi33.
Read on wp.org ↗ - ★★★★★ cidcastello2.0y ago
Excelente plugin!
Read on wp.org ↗ - ★★★★★ patricioposada2.1y ago
It is a truly pain in the A>> to achieve export listings with acf… You must work in this…
Read on wp.org ↗ - ★★★★★ nitroficialiqc2.4y ago
Excelente integración por varias plantillas de WordPress
Read on wp.org ↗
Known vulnerabilities
via Wordfence Intelligence33 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-08-21 CVE-2026-18231 Exposure of Sensitive Information to an Unauthorized Actor Affects < 1.5.7 Patched in 1.5.7
- 2026-08-20 CVE-2026-18653 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.5.7 Patched in 1.5.7
- 2026-08-12 CVE-2026-28001 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.5.4 Patched in 1.5.5
- 2026-08-11 CVE-2026-27538 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.5.4 Patched in 1.5.5
- 2026-08-10 CVE-2026-18474 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.5.5 Patched in 1.5.6
- 2026-08-10 CVE-2026-18230 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.5.5 Patched in 1.5.6
- Medium · 4.3 Directory Kit <= 1.5.4 - Authenticated (Subscriber+) Plugin Settings and API Key Disclosure ↗2026-08-03 CVE-2026-16594 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 1.5.4 Patched in 1.5.5
- 2026-08-03 CVE-2026-16595 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 1.5.4 Patched in 1.5.5
- 2026-08-03 CVE-2026-16589 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.5.4 Patched in 1.5.5
- Medium · 4.3 Directory Kit <= 1.5.4 - Authenticated (Subscriber+) Contact Message and User Data Disclosure ↗2026-08-03 CVE-2026-16590 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 1.5.4 Patched in 1.5.5
- 2026-08-03 CVE-2026-18473 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.5.4 Patched in 1.5.5
- 2026-05-14 CVE-2026-42672 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.5.1 Patched in 1.5.2
- 2026-04-13 CVE-2026-39531 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.5.0 Patched in 1.5.1
- Medium · 5.3 WP Directory Kit <= 1.5.0 - Missing Authorization ↗
- 2026-01-23 CVE-2025-13920 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 1.4.9 Patched in 1.5.0
- 2025-12-12 CVE-2025-13089 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.4.7 Patched in 1.4.8
- Critical · 10.0 WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover ↗2025-12-03 CVE-2025-13390 Incorrect Implementation of Authentication Algorithm Affects 1.4.0 - 1.4.4 Patched in 1.4.5
- 2025-12-01 CVE-2025-13090 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.4.6 Patched in 1.4.7
- 2025-11-26 CVE-2025-13525 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.4.5 Patched in 1.4.6
- 2025-11-20 CVE-2025-13138 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.4.3 Patched in 1.4.4
- Medium · 5.3 WP Directory Kit <= 1.4.0 - Missing Authorization ↗
- 2024-07-04 CVE-2024-37487 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.3.5 Patched in 1.3.6
- 2024-06-26 CVE-2024-37253 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 1.3.6 Patched in 1.3.7
- 2024-04-04 CVE-2024-3217 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.3.0 Patched in 1.3.1
- 2024-03-25 CVE-2024-29774 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.2.9 Patched in 1.3.0
- Medium · 5.3 WP Directory Kit <= 1.2.6 - Missing Authorization ↗
- 2023-06-01 CVE-2023-2835 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.2.3 Patched in 1.2.4
- Critical · 9.8 WP Directory Kit <= 1.1.9 - Unauthenticated Local File Inclusion via wdk_public_action ↗2023-05-26 CVE-2023-2278 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 1.1.9 Patched in 1.2.0
- Medium · 5.4 WP Directory Kit <= 1.1.9 - Open Redirect ↗2023-04-27 CVE-2023-31229 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 1.1.9 Patched in 1.2.0
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 19 languages, 0 at 90% or more
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-06-05 3K+ → 2K+ down after 318 days in tier
- 2025-07-22 4K+ → 3K+ down after 342 days in tier
- 2024-08-14 3K+ → 4K+ up after 3 days in tier
- 2024-08-11 4K+ → 3K+ down after 1 days in tier
- 2024-08-10 3K+ → 4K+ up after 286 days in tier
- 2023-10-29 2K+ → 3K+ up after 212 days in tier
- 2023-03-31 1K+ → 2K+ up
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Directorist: AI-Powered Business Directory, Listings & Classified Ads 20K+ installs · 4.6★ · 3 shared tags A -
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory 10K+ installs · 4.7★ · 3 shared tags A -
HivePress – Business Directory, Listings & Classified Ads Plugin 10K+ installs · 4.8★ · 3 shared tags A -
Classified Listing – AI-Powered Classified ads & Business Directory 9K+ installs · 4.8★ · 3 shared tags A -
Advanced Classifieds & Directory Pro 2K+ installs · 4.6★ · 3 shared tags A -
aDirectory – WP Business Directory Plugin and Classified Ads Listings Directory 300+ installs · 4.4★ · 3 shared tags A
Embed this report card
Drop a live Pulse card for WP Directory Kit into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wpdirectorykit" width="480" height="300" style="border:0" loading="lazy" title="WP Directory Kit — Plugin Pulse"></iframe> WP Directory Kit: 2K+ active installs, 4.9★ (35 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/wpdirectorykit