About our services Security & Risk Analysis

wordpress.org/plugins/about-our-services

The "about our services" plugin is a very simple way, to show your services on your site or blog post. It's have a responsive design an …

0 active installs v1.5.0 PHP 5.6+ WP 5.3+ Updated Unknown
aboutaboutusserviceofferservicesite
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is About our services Safe to Use in 2026?

Generally Safe

Score 100/100

About our services has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "about-our-services" v1.5.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates good security practices by not utilizing dangerous functions, all SQL queries are prepared, and there are no file operations or external HTTP requests, which significantly reduces the attack surface and potential for common vulnerabilities. The presence of nonce checks and capability checks further enhances its security by protecting against common attack vectors.

However, a notable concern arises from the output escaping. With 44% of outputs properly escaped, this indicates that a significant portion of the plugin's output is not being sanitized, leaving it vulnerable to Cross-Site Scripting (XSS) attacks. While the taint analysis shows no unsanitized flows, the low percentage of proper output escaping is a direct indicator of potential XSS risks. The plugin's history of zero known CVEs is a positive sign, suggesting a well-maintained and relatively secure codebase. Nevertheless, the output escaping issue remains a critical weakness that needs to be addressed.

In conclusion, while the "about-our-services" plugin has several strengths, particularly in its handling of SQL and lack of dangerous functions, the insufficient output escaping is a significant weakness that introduces a notable risk of XSS vulnerabilities. Addressing this by ensuring all output is properly escaped should be the primary focus for improving its security.

Key Concerns

  • Insufficient output escaping (44% proper)
Vulnerabilities
None known

About our services Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

About our services Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
16 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

44% escaped36 total outputs
Attack Surface

About our services Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[thaos] inc\thaos-shortcode.php:26
WordPress Hooks 17
actionplugins_loadedinc\thaos-admin.php:33
actionadmin_enqueue_scriptsinc\thaos-admin.php:36
actionadmin_menuinc\thaos-help.php:31
actionadmin_initinc\thaos-post-metabox.php:23
actionsave_postinc\thaos-post-metabox.php:163
actionadmin_initinc\thaos-settings.php:81
actionadmin_menuinc\thaos-settings.php:176
actioninitinc\thaos-types.php:23
actioninitinc\thaos-types.php:26
filterpost_updated_messagesinc\thaos-types.php:112
actionmanage_thaos_posts_custom_columninc\thaos-types.php:156
filtermanage_edit-thaoss_categories_columnsinc\thaos-types.php:171
actionmanage_thaoss_categories_custom_columninc\thaos-types.php:191
filtermanage_thaos_posts_columnsinc\thaos-types.php:207
actionwp_enqueue_scriptsinc\thaos-user.php:23
actionwp_enqueue_scriptsinc\thaos-user.php:31
actioninitth-about-our-services.php:37
Maintenance & Trust

About our services Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedUnknown
PHP min version5.6
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

About our services Developer Profile

Triopsi

7 plugins · 60 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect About our services

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/about-our-services/assets/css/editor-admin.css/wp-content/plugins/about-our-services/assets/js/logic-form.js/wp-content/plugins/about-our-services/assets/js/thaos-admin-script-color.js/wp-content/plugins/about-our-services/assets/css/front-style.css
Version Parameters
th-about-our-services/style.css?ver=th-about-our-services/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
thaos-services-boxesthaos-boxes-contentthaos-box-titlethaos-box-descriptionthaos-box-button
Data Attributes
data-link-targetdata-show-titledata-orderbydata-orderdata-servicenamedata-id+3 more
JS Globals
thaos_admin_script_colorlogic_form
Shortcode Output
[thaos][thaos servicename=[thaos id=[thaos category=
FAQ

Frequently Asked Questions about About our services