North Extensions Security & Risk Analysis

wordpress.org/plugins/acosmin-north-extensions

Adds front page sections (Instagram, Ads), a post title design option and other extensions to North WordPress theme.

0 active installs v1.0.0 PHP + WP 4.6+ Updated Jun 24, 2017
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is North Extensions Safe to Use in 2026?

Generally Safe

Score 85/100

North Extensions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "acosmin-north-extensions" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a limited attack surface. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and performing a high percentage (84%) of output escaping, which mitigates common vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The presence of nonce and capability checks further enhances its security, ensuring proper authorization for its operations.

However, a potential concern lies within the use of a dangerous function, specifically `preg_replace(/e)`. While the static analysis doesn't explicitly detail a vulnerable flow, this pattern is historically associated with Remote Code Execution (RCE) vulnerabilities when not handled with extreme caution and proper sanitization of user-supplied data. The plugin's vulnerability history is currently clean, with no recorded CVEs, which is positive. However, this could be due to the plugin being relatively new or simply not having been targeted or audited extensively. The presence of external HTTP requests, while not inherently a vulnerability, warrants careful scrutiny to ensure they do not introduce risks like SSRF or data leakage.

In conclusion, the plugin has a good foundation with a small attack surface and robust data handling for SQL. The primary area for caution is the `preg_replace(/e)` usage and the external HTTP requests. A thorough dynamic analysis and security audit, focusing on how these specific elements are utilized with user input, would be highly recommended to confirm the absence of exploitable vulnerabilities.

Key Concerns

  • Use of dangerous function preg_replace(/e)
  • External HTTP requests present
Vulnerabilities
None known

North Extensions Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

North Extensions Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

North Extensions Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
19
97 escaped
Nonce Checks
1
Capability Checks
6
File Operations
0
External Requests
3
Bundled Libraries
0

Dangerous Functions Found

preg_replace(/e)preg_replace('/<em>(.*?)<\/emodules/title-design/init.php:145

Output Escaping

84% escaped116 total outputs
Attack Surface

North Extensions Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 40
actioncustomize_registercustomizer/init.php:17
actionadmin_enqueue_scriptsinc/enqueue-backend.php:31
actionadmin_menumodules/title-design/init.php:9
actionsave_postmodules/title-design/init.php:10
filterthe_titlemodules/title-design/init.php:11
actionnorthe__section_adssections/ads/ads-tmpl.php:15
filternorth___section_category_defaultssections/category/category.php:10
filternorth___section_category_optionssections/category/category.php:11
filternorth___section_category_updatesections/category/category.php:12
filternorth___section_category_fieldssections/category/category.php:13
actionnorth__sec_tmpl_cat_side_widgetssections/category/category.php:14
actionwidgets_initsections/init.php:10
filternorth_customizer_js_settingssections/init.php:11
actionnorthe__section_instagramsections/instagram/instagram-tmpl.php:15
actionnorthe__section_instagramsections/instagram/instagram-tmpl.php:16
actionnorthe__section_instagramsections/instagram/instagram-tmpl.php:17
actionnorthe__section_instagramsections/instagram/instagram-tmpl.php:18
actionnorthe__section_instagram_headersections/instagram/instagram-tmpl.php:20
actionnorthe__section_instagram_headersections/instagram/instagram-tmpl.php:21
actionnorthe__section_instagram_headersections/instagram/instagram-tmpl.php:22
actionnorthe__section_instagram_headersections/instagram/instagram-tmpl.php:23
actionnorthe__section_instagram_headersections/instagram/instagram-tmpl.php:24
actionnorthe__section_instagram_initsections/instagram/instagram-tmpl.php:26
actionnorthe__section_instagram_initsections/instagram/instagram-tmpl.php:27
actionnorthe__section_instagram_initsections/instagram/instagram-tmpl.php:28
actionnorthe__section_instagram_initsections/instagram/instagram-tmpl.php:29
actionadmin_menusettings-pages/instagram.php:27
actionadmin_initsettings-pages/instagram.php:28
filterplugin_action_linkssettings-pages/instagram.php:30
actionadmin_enqueue_scriptssettings-pages/instagram.php:32
actionnorthe__widget_adswidgets/ads/ads-tmpl.php:15
actionwidgets_initwidgets/init.php:10
actionnorthe__widget_instagramwidgets/instagram/instagram-tmpl.php:15
actionnorthe__widget_instagramwidgets/instagram/instagram-tmpl.php:16
actionnorthe__widget_instagramwidgets/instagram/instagram-tmpl.php:17
actionnorthe__widget_instagramwidgets/instagram/instagram-tmpl.php:18
actionnorthe__widget_instagramwidgets/instagram/instagram-tmpl.php:19
actionnorthe__widget_instagram_wrapwidgets/instagram/instagram-tmpl.php:21
actionnorthe__widget_instagram_wrapwidgets/instagram/instagram-tmpl.php:22
actionnorthe__widget_instagram_wrapwidgets/instagram/instagram-tmpl.php:23
Maintenance & Trust

North Extensions Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJun 24, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

North Extensions Alternatives

No alternatives data available yet.

Developer Profile

North Extensions Developer Profile

acosmin

6 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect North Extensions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/acosmin-north-extensions/assets/css/admin.css/wp-content/plugins/acosmin-north-extensions/assets/js/admin.js/wp-content/plugins/acosmin-north-extensions/assets/js/instagram.js
Version Parameters
acosmin-north-extensions/assets/css/admin.css?ver=acosmin-north-extensions/assets/js/admin.js?ver=acosmin-north-extensions/assets/js/instagram.js?ver=

HTML / DOM Fingerprints

CSS Classes
northe-instagram-widgetbutton-connectnorthe-instagarm-connected
Data Attributes
id="northe-instagram-settings_access-token"
JS Globals
northe_instagram_admin
FAQ

Frequently Asked Questions about North Extensions