
Premium Portfolio Features for Phlox theme Security & Risk Analysis
wordpress.org/plugins/auxin-portfolioShowcase your projects beautifully in Phlox theme
Is Premium Portfolio Features for Phlox theme Safe to Use in 2026?
Generally Safe
Score 89/100Premium Portfolio Features for Phlox theme has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin auxin-portfolio v2.3.12 presents a mixed security posture. While the static analysis indicates a relatively small attack surface with no direct unprotected entry points and the use of prepared statements for SQL queries, there are concerning indicators regarding output escaping. A significant percentage of output (43%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output. The presence of unsanitized paths in taint flows, although not classified as critical or high severity in this analysis, suggests a potential for insecure file operations or include/require statements that could be exploited if input is not rigorously validated.
The plugin's vulnerability history is a major concern. With four known CVEs, including one critical and one high severity, and a recent vulnerability recorded in late 2025, the plugin has a demonstrated track record of security flaws. The historical prevalence of Remote File Inclusion and Cross-site Scripting vulnerabilities indicates recurring weaknesses in input validation and file handling. Although there are currently no unpatched CVEs, the history suggests a consistent need for vigilance and prompt patching when new vulnerabilities are discovered. The combination of unescaped output, potential for unsanitized path flows, and a history of critical vulnerabilities points to a need for caution when using this plugin.
Key Concerns
- Significant percentage of unescaped output
- Taint flows with unsanitized paths
- History of critical severity CVEs
- History of high severity CVEs
- History of medium severity CVEs
- Bundled library (TinyMCE) may be outdated
Premium Portfolio Features for Phlox theme Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Premium Portfolio Features for Phlox theme <= 2.3.10 - Unauthenticated Local File Inclusion via args[extra_template_path]
Premium Portfolio Features for Phlox theme <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Premium Portfolio Features for Phlox theme <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via ' Grid Portfolios'
Phlox Portfolio <= 2.3.1 - Unauthenticated Local File Inclusion
Premium Portfolio Features for Phlox theme Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Premium Portfolio Features for Phlox theme Attack Surface
AJAX Handlers 2
WordPress Hooks 38
Maintenance & Trust
Premium Portfolio Features for Phlox theme Maintenance & Trust
Maintenance Signals
Community Trust
Premium Portfolio Features for Phlox theme Alternatives
Shortcodes and extra features for Phlox theme
auxin-elements
Powerful and comprehensive plugin that extends the functionality of Phlox Elementor theme.
PowerFolio – Portfolio & Image Gallery for Elementor
portfolio-elementor
A powerful portfolio and gallery plugin for WP, Elementor and Gutenberg. Create portfolio and image galleries in seconds using any page builder!
Elfi Masonry – Filterable Portfolio & Masonry Gallery Addon for Elementor
elfi-masonry-addon
"ELFI Masonry Addon" is a filterable and gallery showcase addon for Elementor page builder.
Gallery Tile Links (for Elementor)
gallery-tile-links-elementor
Give each image in Elementor’s built-in Image Gallery its own URL. Masonry/Classic layouts supported. Server-side, no JS, no order hacks.
mFolio Lite
mfolio-lite
Short Description: Create modern portfolios with an all-in-one Elementor portfolio plugin for WordPress.
Premium Portfolio Features for Phlox theme Developer Profile
6 plugins · 310K total installs
How We Detect Premium Portfolio Features for Phlox theme
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auxin-portfolio/public/assets/js/portfolio.js/wp-content/plugins/auxin-portfolio/public/assets/css/main.cssauxin-portfolio/main.css?ver=auxin-portfolio/portfolio.js?ver=HTML / DOM Fingerprints
aux-portfolio-gridaux-portfolio-item-wrapperaux-portfolio-item-metaaux-portfolio-terms<!-- Auxin Portfolio Loop --><!-- Auxin Portfolio Item -->data-auxin-portfolio-iddata-auxin-portfolio-layoutwindow.auxpfo/wp-json/auxin-portfolio/v1[auxin_portfolio[auxin_portfolio_gallery