
Bonkers Addons Security & Risk Analysis
wordpress.org/plugins/bonkers-addonsThis plugins adds several options in the customizer to use with your theme.
Is Bonkers Addons Safe to Use in 2026?
Generally Safe
Score 85/100Bonkers Addons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bonkers-addons" plugin v1.0.1 exhibits a mixed security posture. On the positive side, it shows good practices in its handling of SQL queries, utilizing prepared statements exclusively, and has a high percentage of properly escaped output. The complete absence of dangerous functions, file operations, external HTTP requests, and known vulnerabilities is also a strong indicator of a secure codebase in these areas. However, the presence of two AJAX handlers without authentication checks represents a significant security concern, as these could be exploited by unauthenticated users to perform unintended actions. The lack of nonce checks on these AJAX endpoints exacerbates this risk, making cross-site request forgery (CSRF) a plausible attack vector.
The taint analysis shows no critical or high severity flows, which is reassuring. However, the presence of three flows with unsanitized paths, even if not deemed critical in this analysis, indicates potential for unexpected behavior or information disclosure if these paths are used maliciously. The plugin's vulnerability history is currently clean, suggesting diligence from the developers or a lack of historical targeting. Nevertheless, the identified unprotected AJAX handlers are the most immediate and actionable security risks that require attention.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks on AJAX handlers
- Taint flows with unsanitized paths
Bonkers Addons Security Vulnerabilities
Bonkers Addons Release Timeline
Bonkers Addons Code Analysis
Output Escaping
Data Flow Analysis
Bonkers Addons Attack Surface
AJAX Handlers 2
Shortcodes 7
WordPress Hooks 16
Maintenance & Trust
Bonkers Addons Maintenance & Trust
Maintenance Signals
Community Trust
Bonkers Addons Alternatives
Matcha Extra
matcha-extra
Used for adding extra features to WP Matcha Themes.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Desert Companion
desert-companion
Desert Companion Enhances Desert Themes with additional functionality.
Arile Extra
arile-extra
Arile Extra is a companion plugin for ArileWP WordPress theme by ThemeArile.
Shapely Companion
shapely-companion
Shapely Companion is a companion plugin for Shapely WordPress theme by Colorlib.com.
Bonkers Addons Developer Profile
11 plugins · 420K total installs
How We Detect Bonkers Addons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bonkers-addons/custom-controls/class-bonkers-radio-image-control.php/wp-content/plugins/bonkers-addons/custom-controls/class-bonkers-addons-display-text-control.php/wp-content/plugins/bonkers-addons/shortcodes/product-carousel.phpHTML / DOM Fingerprints
bonkers-intro-lineql_border_btn<!-- Front Page Sections --><!-- Welcome --><!-- Services -->data-sectionid="bonkers_addons_welcome_section"data-sectionid="bonkers_addons_services_section"window.bonkers_addons_sanitize_text_htmlwindow.bonkers_addons_sanitize_textwindow.bonkers_addons_sanitize_urlwindow.bonkers_addons_sanitize_integer[product_carousel]