
BlogWings Companion Security & Risk Analysis
wordpress.org/plugins/blogwings-companionBlogWings Customiser plugin will add lot of features.
Is BlogWings Companion Safe to Use in 2026?
Generally Safe
Score 85/100BlogWings Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "blogwings-companion" plugin version 1.0.7 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong practices in its handling of SQL queries, exclusively using prepared statements, and it has no recorded vulnerability history, suggesting a good track record of security. The limited attack surface, with only one shortcode and no AJAX handlers, REST API routes, or cron events, is also a positive indicator, especially since these entry points are not directly exposed for unauthenticated access.
However, there are significant concerns arising from the static analysis. The presence of a dangerous `create_function` call is a major red flag, as it can lead to code injection vulnerabilities if user-supplied data is used within its parameters without proper sanitization. Furthermore, a substantial portion of output (66%) is not properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website if the unescaped output contains user-controlled data.
The absence of nonce checks and capability checks for its single entry point (the shortcode) also presents a weakness. While there are no external HTTP requests or file operations, and the SQL is secure, these omissions in authorization and output sanitization are critical points of concern that could be exploited. The lack of taint analysis results for this version also makes it difficult to assess the potential impact of the identified code signals.
Key Concerns
- Dangerous function create_function found
- Significant amount of unescaped output detected
- Missing nonce checks on entry points
- Missing capability checks on entry points
BlogWings Companion Security Vulnerabilities
BlogWings Companion Code Analysis
Dangerous Functions Found
Output Escaping
BlogWings Companion Attack Surface
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
BlogWings Companion Maintenance & Trust
Maintenance Signals
Community Trust
BlogWings Companion Alternatives
Hunk Companion
hunk-companion
Adds customizer settings and controls to the Gogo Theme.
LSX Blog Customizer
lsx-blog-customizer
The LSX Blog Customiser will let you create the type of blog you want, showcasing your content in the layout and with the right metadata that you deci …
Kirki Customizer Framework
kirki
The Ultimate Customizer Framework for WordPress Theme Developers
SiteOrigin Widgets Bundle
so-widgets-bundle
Essential elements for modern websites. Add buttons, sliders, heroes, maps, images, carousels, features, icons, more. Create dynamic pages easily.
LoginPress | wp-login Custom Login Page Customizer
loginpress
LoginPress is a Custom Login Page Customizer plugin allows you to easily customize the layout of login, admin login, client login, register pages.
BlogWings Companion Developer Profile
1 plugin · 50 total installs
How We Detect BlogWings Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blogwings-companion/admin/color/color.css/wp-content/plugins/blogwings-companion/admin/color/color.jsblogwings-companion/admin/color/color.css?ver=1.0.0HTML / DOM Fingerprints
alpha-color-controldata-show-opacitydata-default-colorBLOGWINGS_COMPANION_PLUGIN_URLportfoliolinewpLocalize