
AWcode Toolkit Security & Risk Analysis
wordpress.org/plugins/awcode-toolkitAWcode Toolkit provides a collection of useful tools and functions for Wordpress site owners
Is AWcode Toolkit Safe to Use in 2026?
Generally Safe
Score 98/100AWcode Toolkit has a strong security track record. Known vulnerabilities have been patched promptly.
The awcode-toolkit plugin v1.0.24 presents a mixed security posture. While it demonstrates good practices in utilizing prepared statements for SQL queries and properly escaping a high percentage of output, several areas raise concerns. The presence of a dangerous `unserialize` function is a significant red flag, especially when combined with a high number of unsanitized taint flows. Furthermore, the attack surface includes two AJAX handlers without authentication checks, creating a direct pathway for potential unauthorized actions. The vulnerability history, while showing no currently unpatched CVEs, reveals a pattern of past medium-severity issues related to CSRF and XSS, suggesting a recurring need for careful input validation and output sanitization. The existence of two unprotected AJAX endpoints and the use of `unserialize` without apparent validation are the most immediate risks.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function: unserialize
- High number of unsanitized taint flows
- Past CSRF and XSS vulnerabilities
AWcode Toolkit Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
AWcode Toolkit <= 1.0.18 - Cross-Site Request Forgery to Stored Cross-Site Scripting
AWcode Toolkit <= 1.0.14 - Reflected Cross-Site Scripting
AWcode Toolkit Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
AWcode Toolkit Attack Surface
AJAX Handlers 4
WordPress Hooks 32
Maintenance & Trust
AWcode Toolkit Maintenance & Trust
Maintenance Signals
Community Trust
AWcode Toolkit Alternatives
Kitgenix CAPTCHA for Cloudflare Turnstile
kitgenix-captcha-for-cloudflare-turnstile
Add Cloudflare Turnstile to WordPress, WooCommerce, Elementor, and popular form plugins. Privacy-first spam protection with server-side verification.
Beetle Tracking – Cloudflare Zaraz for WooCommerce
beetle-tracking
Track Key Events and Parameters on WordPress Effortlessly with Cloudflare Zaraz's Real Edge Server-Side Tracking Technology.
myPortfolio Plus
my-portfolio-plus
My Portfolio Plus enables a Web Developer/Designer to create a Wordpress Portfolio for their work in a very easy way.
WP Folio
wp-foliolio
WP-Foliolio enables a Web Developer/Designer to create a Wordpress Portfolio for their work with wp's familiar content creation system.
EdgeMail
edgemail
Replace WordPress transactional email with Cloudflare Worker endpoint integration.
AWcode Toolkit Developer Profile
4 plugins · 110 total installs
How We Detect AWcode Toolkit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/awcode-toolkit/includes/class.awtoolkit-remote.php/wp-content/plugins/awcode-toolkit/includes/class.awtoolkit-general.php/wp-content/plugins/awcode-toolkit/includes/class.awtoolkit-setting.php/wp-content/plugins/awcode-toolkit/includes/class.awtoolkit-woocommerce.php/wp-content/plugins/awcode-toolkit/includes/class.awtoolkit-woo-product-suppliers.php/wp-content/plugins/awcode-toolkit/aw-toolkit.phpHTML / DOM Fingerprints
wp-smush-exceed-limitwp-smush-resume-bulk-smushwp-smush-bulk-progress-bar-wrapperMutationObserverwindow$/awtoolkit/v1/status/awtoolkit/v1/plugins/awtoolkit/v1/themes/awtoolkit/v1/users/awtoolkit/v1/upgrade/core/awtoolkit/v1/upgrade/plugin/awtoolkit/v1/upgrade/theme