
aThemes Starter Sites Security & Risk Analysis
wordpress.org/plugins/athemes-starter-sitesWe've got a full and ever-growing library stocked with ready-made templates for any kind of business.
Is aThemes Starter Sites Safe to Use in 2026?
Generally Safe
Score 99/100aThemes Starter Sites has a strong security track record. Known vulnerabilities have been patched promptly.
The 'athemes-starter-sites' plugin v1.1.7 exhibits a generally good security posture with several strengths, including a high percentage of prepared SQL statements and properly escaped output. The absence of critical or high-severity taint analysis findings and a lack of currently unpatched CVEs are positive indicators. However, a notable concern is the presence of 8 AJAX handlers that lack authentication checks, representing a significant attack surface that could be exploited by unauthenticated users. The plugin's history shows one medium-severity Cross-Site Scripting (XSS) vulnerability, suggesting a need for continued vigilance in input sanitization and output encoding, even with the current high rate of proper escaping.
Despite the positive aspects like a lack of critical code signals and a recent focus on patching vulnerabilities, the unprotected AJAX endpoints present a tangible risk. While taint analysis shows no immediate critical or high flows, the 8 unauthenticated entry points are a direct invitation for potential abuse. The past XSS vulnerability, though resolved, serves as a reminder that even with good practices, subtle flaws can emerge. Overall, the plugin is on solid ground with good defensive programming, but the identified unauthenticated AJAX handlers require immediate attention to fully secure it.
Key Concerns
- Unprotected AJAX handlers detected
- Past medium severity XSS vulnerability
aThemes Starter Sites Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
aThemes Starter Sites <= 1.0.53 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
aThemes Starter Sites Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
aThemes Starter Sites Attack Surface
AJAX Handlers 26
WordPress Hooks 72
Maintenance & Trust
aThemes Starter Sites Maintenance & Trust
Maintenance Signals
Community Trust
aThemes Starter Sites Alternatives
Emoza Starter Sites
emoza-starter-sites
Quickly import demo content for the Emoza theme and launch your site with a professional look in minutes!
Aarambha Demo Sites
aarambha-demo-sites
Import Aarambha Themes inbuilt themes demo content, widgets and its all settings with one click.
Xolo Websites
xolo-websites
FREE TEMPLATES FOR ELEMENTOR PAGE BUILDER
YalaThemes ToolKit
yala-themes-toolkit
Import YalaThemes Official Themes Demo Content, Widgets and Theme settings with just one click.
Novex Demo Importer
novex-demo-importer
One click demo import for Novex themes — instantly import free & premium Elementor sites to launch a fully designed WordPress site in seconds.
aThemes Starter Sites Developer Profile
94 plugins · 23.5M total installs
How We Detect aThemes Starter Sites
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/athemes-starter-sites/assets/js/select2.min.js/wp-content/plugins/athemes-starter-sites/assets/js/stylefire.min.js/wp-content/plugins/athemes-starter-sites/assets/js/popmotion.global.min.js/wp-content/plugins/athemes-starter-sites/assets/js/select2.min.js/wp-content/plugins/athemes-starter-sites/assets/js/stylefire.min.js/wp-content/plugins/athemes-starter-sites/assets/js/popmotion.global.min.jsathemes-starter-sites/athemes-starter-sites.php?ver=select2.min.js?ver=stylefire.min.js?ver=popmotion.global.min.js?ver=HTML / DOM Fingerprints
ATSS_URL