Bootitems Core Security & Risk Analysis

wordpress.org/plugins/bootitems-core

Bootitems Core is a companion plugin for Bootitems Themes, which provides core functionality and extends free themes features by adding functionality …

10 active installs v1.0.0 PHP 5.6+ WP 5.0+ Updated Jul 29, 2022
bootitems-corecontentdemoimporttemplate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bootitems Core Safe to Use in 2026?

Generally Safe

Score 85/100

Bootitems Core has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "bootitems-core" plugin v1.0.0 exhibits a generally good security posture in several areas, particularly with its handling of SQL queries and output escaping, suggesting developers have implemented some common security best practices. The absence of known CVEs and a clean vulnerability history are positive indicators. However, the presence of an unprotected AJAX handler represents a significant concern, forming a critical entry point into the plugin's functionality. While the code analysis shows no overtly dangerous functions or taint flows indicating immediate critical vulnerabilities, this single unprotected endpoint could be exploited by an attacker to trigger unintended actions or access sensitive data if it performs any operations that are not sufficiently secured by other means.

The plugin's reliance on a bundled library, Freemius v1.0, also warrants attention. While not explicitly flagged as outdated in the provided data, bundled libraries can become security risks if not regularly updated, as they may inherit vulnerabilities from their parent projects. The overall risk is currently moderate, leaning towards higher due to the unprotected AJAX handler. Addressing this single point of exposure should be the immediate priority for improving the plugin's security.

Key Concerns

  • Unprotected AJAX handler detected
  • Bundled library (Freemius v1.0) may be outdated
Vulnerabilities
None known

Bootitems Core Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Bootitems Core Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
30
322 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

91% escaped352 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
start_el (inc\menu\bootitems_edit_walker.php:38)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Bootitems Core Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_bootitems_core_getting_startedclass\class-bootitems-core.php:144
WordPress Hooks 18
actionplugins_loadedclass\class-bootitems-core.php:133
actionadmin_initclass\class-bootitems-core.php:141
actionadvanced_import_demo_listsclass\class-bootitems-core.php:142
actionadmin_menuclass\class-bootitems-core.php:143
actionadmin_enqueue_scriptsclass\class-bootitems-core.php:163
actionadmin_enqueue_scriptsclass\class-bootitems-core.php:164
actionwp_enqueue_scriptsclass\class-bootitems-core.php:179
actionwp_enqueue_scriptsclass\class-bootitems-core.php:180
actionadmin_noticesclass\class-bootitems-core.php:206
actionadvanced_import_is_pro_activeinc\functions.php:90
filterwp_setup_nav_menu_iteminc\menu\bootitems-megamenu.php:6
actionwp_update_nav_menu_iteminc\menu\bootitems-megamenu.php:8
filterwp_edit_nav_menu_walkerinc\menu\bootitems-megamenu.php:10
actionadmin_menuinc\register-menu.php:17
actionwidgets_initinc\widgets\about-info.php:112
actionwidgets_initinc\widgets\contact-info.php:112
actionwidgets_initinc\widgets\recent-posts.php:110
actionwidgets_initinc\widgets\social-profiles.php:136
Maintenance & Trust

Bootitems Core Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 29, 2022
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Bootitems Core Developer Profile

Masud Rana

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bootitems Core

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bootitems-core/inc/bootitems-widgets.js/wp-content/plugins/bootitems-core/public/css/bootitems-core-public.css
Script Paths
/wp-content/plugins/bootitems-core/freemius/start.php
Version Parameters
bootitems-core/public/css/bootitems-core-public.css?ver=bootitems-core/inc/bootitems-widgets.js?ver=

HTML / DOM Fingerprints

CSS Classes
bootitems-core-demo-section
Data Attributes
data-bootitems-id
JS Globals
bootitems_core_ajax_object
Shortcode Output
[bootitems_demo_import]
FAQ

Frequently Asked Questions about Bootitems Core