
Ashe Extra Security & Risk Analysis
wordpress.org/plugins/ashe-extraAdds One Click Demo Import functionality for Ashe theme.
Is Ashe Extra Safe to Use in 2026?
Generally Safe
Score 91/100Ashe Extra has a strong security track record. Known vulnerabilities have been patched promptly.
The "ashe-extra" v1.3 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a complete absence of critical or high-severity issues within the analyzed code, including no dangerous functions, no unsanitized taint flows, and all identified AJAX handlers and shortcodes have authorization checks. The plugin also demonstrates good practices with nonce checks and capability checks on all identified entry points. However, there are notable areas for improvement. The output escaping is only properly implemented in 36% of cases, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sanitization. While the SQL queries are predominantly prepared, 29% are not, posing a potential SQL injection risk in those specific instances. The vulnerability history is a significant concern, with two known medium-severity CVEs, both related to Missing Authorization. The fact that these are not currently unpatched is positive, but the recurring nature of authorization flaws suggests a persistent weakness in how user permissions are handled in certain plugin functionalities. Overall, while the current code shows improvements in immediate attack surface protection, the historical vulnerability patterns and less-than-ideal output escaping and SQL preparation practices warrant caution.
Key Concerns
- Output escaping is poorly implemented (36%)
- SQL queries not always prepared (29%)
- History of medium severity CVEs (2)
Ashe Extra Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Ashe Extra <= 1.2.92 - Missing Authorization
Ashe Extra <= 1.2.91 - Missing Authorization via multiple AJAX actions
Ashe Extra Code Analysis
SQL Query Safety
Output Escaping
Ashe Extra Attack Surface
AJAX Handlers 6
WordPress Hooks 11
Maintenance & Trust
Ashe Extra Maintenance & Trust
Maintenance Signals
Community Trust
Ashe Extra Alternatives
No alternatives data available yet.
Ashe Extra Developer Profile
9 plugins · 766K total installs
How We Detect Ashe Extra
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ashe-extra/assets/images/cf7.png/wp-content/plugins/ashe-extra/assets/images/instagram-feed.png/wp-content/plugins/ashe-extra/assets/images/mailchimp.png/wp-content/plugins/ashe-extra/assets/images/recent-posts.png/wp-content/plugins/ashe-extra/assets/images/royal-elementor-addons.png/wp-content/plugins/ashe-extra/assets/js/admin-scripts.js/wp-content/plugins/ashe-extra/assets/js/admin-scripts.jsashe-extra/assets/js/admin-scripts.js?ver=HTML / DOM Fingerprints
extra-options-page-wrapextra-optionsashextra-plugin-activationplugin-boxafter-import-noticevisit-websiteid="contact_from_7"id="instagram_feed"id="mailchimp_newsletter"id="recent_posts" AsheExtraashe_extra_ajax_obj/wp-json/ashextra/v1/import/wp-json/ashextra/v1/demo-content