
Apollo13 Framework Extensions Security & Risk Analysis
wordpress.org/plugins/apollo13-framework-extensionsAdds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Is Apollo13 Framework Extensions Safe to Use in 2026?
Generally Safe
Score 95/100Apollo13 Framework Extensions has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin 'apollo13-framework-extensions' v1.9.9 exhibits a mixed security posture. On the positive side, static analysis shows a strong adherence to secure coding practices, with 100% of SQL queries using prepared statements, a high percentage of output escaping (84%), and the presence of nonce and capability checks on entry points. Crucially, no critical or high severity taint flows were identified, and all entry points appear to have authorization checks, contributing to a reduced immediate risk from directly exploitable code flaws. However, the plugin's history of 6 known medium severity vulnerabilities, including Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Missing Authorization issues, indicates a pattern of past exploitable weaknesses that, while currently patched, suggest an underlying susceptibility. The presence of the `unserialize` function, a known source of vulnerabilities if not handled with extreme care, is also a concern, though its exploitation is not evident in the taint analysis.
Despite the current lack of unpatched CVEs and critical taint flows, the historical prevalence of medium-severity vulnerabilities warrants attention. This suggests that while developers are addressing issues, there may be recurring patterns or oversight in certain areas. The attack surface, while protected by checks, is still present across AJAX handlers and shortcodes. The plugin's strengths lie in its implemented security mechanisms like prepared statements and output escaping. The primary weakness identified is its historical vulnerability record and the presence of a potentially dangerous function. Overall, the plugin is in a relatively secure state for this version, but vigilance regarding its past exploitability is advised.
Key Concerns
- History of 6 medium severity vulnerabilities
- Presence of dangerous function (unserialize)
Apollo13 Framework Extensions Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Apollo13 Framework Extension <= 1.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via `a13_alt_link` Parameter
Apollo13 Framework Extensions <= 1.9.3 - Authenticated (Author+) Stored Cross-Site Scripting
Apollo13 Framework Extensions <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Apollo13 Framework Extensions <= 1.9.1 - Cross-Site Request Forgery
Apollo13 Framework Extensions <= 1.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Apollo13 Framework Extensions <= 1.8.10 - Missing Authorization
Apollo13 Framework Extensions Release Timeline
Apollo13 Framework Extensions Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Apollo13 Framework Extensions Attack Surface
AJAX Handlers 5
Shortcodes 17
WordPress Hooks 94
Maintenance & Trust
Apollo13 Framework Extensions Maintenance & Trust
Maintenance Signals
Community Trust
Apollo13 Framework Extensions Alternatives
WebMan Amplifier
webman-amplifier
Amplifies functionality of WP themes. Provides custom post types, shortcodes, metaboxes, icons. Theme developer's best friend!
SFN Easy FAQ Manager
wordpress-faq-manager
Uses custom post types and taxonomies to manage an FAQ section for your site.
Matcha Extra
matcha-extra
Used for adding extra features to WP Matcha Themes.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Apollo13 Framework Extensions Developer Profile
3 plugins · 60K total installs
How We Detect Apollo13 Framework Extensions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/apollo13-framework-extensions/assets/js/a13-slider.js/wp-content/plugins/apollo13-framework-extensions/assets/js/anime.min.js/wp-content/plugins/apollo13-framework-extensions/assets/js/a13-slider.js/wp-content/plugins/apollo13-framework-extensions/assets/js/anime.min.js/wp-content/plugins/apollo13-framework-extensions/assets/js/a13-slider.js?ver=/wp-content/plugins/apollo13-framework-extensions/assets/js/anime.min.js?ver=HTML / DOM Fingerprints
a13_class_a13_count_downflippingtimecountcurrtopnext+2 moredata-styledata-weeksdata-daysdata-hoursdata-minutesdata-seconds+1 more<div class="a13_count_down<style> .a13_class_<div class="time <%= label %><span class="count curr top