
Century ToolKit Security & Risk Analysis
wordpress.org/plugins/century-toolkitToolKit for WordPress themes and demo content importer for themes.
Is Century ToolKit Safe to Use in 2026?
Use With Caution
Score 63/100Century ToolKit has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "century-toolkit" plugin v1.2.1 exhibits a mixed security posture. While it demonstrates strengths in its use of prepared statements for SQL queries and the absence of critical or high-severity taint flows, several concerns are present. The plugin has a concerning number of AJAX handlers, with one lacking any authentication check, presenting a significant attack vector. Furthermore, the presence of the `unserialize` function is a known risk if not handled with extreme care, as it can lead to remote code execution vulnerabilities if it processes untrusted input. The vulnerability history reveals a medium-severity CVE, specifically a Cross-Site Request Forgery (CSRF), which is concerning as it remains unpatched. The recurrence of CSRF vulnerabilities in the past suggests a potential pattern of insecure handling of user actions. Overall, the plugin has areas of good practice but is hampered by an exposed AJAX endpoint, the use of a dangerous function, and an unpatched historical vulnerability.
Key Concerns
- Unprotected AJAX handler
- Presence of unserialize function
- Unpatched medium severity CVE
- Below average output escaping (66%)
Century ToolKit Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Century ToolKit <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Plugin Activation
Century ToolKit Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Century ToolKit Attack Surface
AJAX Handlers 8
WordPress Hooks 10
Maintenance & Trust
Century ToolKit Maintenance & Trust
Maintenance Signals
Community Trust
Century ToolKit Alternatives
Mirrorgrid Demo Importer
mirrorgrid-demo-importer
ToolKit for Mirrorgrid themes and demo content importer for themes.
Rara One Click Demo Import
rara-one-click-demo-import
Make your website look like the live demo of the theme with a click!
AF Companion – Build Stylish WordPress Websites in Minutes – No Coding, Just Click and Go! Starter Sites Importer for WordPress
af-companion
Quickly import live demo content, widgets and settings with one click
Themebeez Toolkit
themebeez-toolkit
A essential toolkit for WordPress themes developed by us. Themebeez Toolkit helps you to import dummy demo contents. It also adds extra features & …
SKT Themes Demo Import
skt-themes-demo-importer
Live demo content can be imported quickly in just one click including all widgets and settings.
Century ToolKit Developer Profile
3 plugins · 810 total installs
How We Detect Century ToolKit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/century-toolkit/assets/css/style.css/wp-content/plugins/century-toolkit/assets/js/script.js/wp-content/plugins/century-toolkit/assets/css/select2.min.css/wp-content/plugins/century-toolkit/assets/js/select2.min.js/wp-content/plugins/century-toolkit/assets/js/backend.js/wp-content/plugins/century-toolkit/assets/css/backend.css/wp-content/plugins/century-toolkit/assets/js/script.js/wp-content/plugins/century-toolkit/assets/js/select2.min.js/wp-content/plugins/century-toolkit/assets/js/backend.jscentury-toolkit/assets/css/style.css?ver=century-toolkit/assets/js/script.js?ver=century-toolkit/assets/css/select2.min.css?ver=century-toolkit/assets/js/select2.min.js?ver=century-toolkit/assets/js/backend.js?ver=century-toolkit/assets/css/backend.css?ver=HTML / DOM Fingerprints
century-toolkit-import-wrapcentury-toolkit-import-introcentury-toolkit-import-navcentury-toolkit-import-nav-stepcentury-toolkit-import-nav-step-activecentury-toolkit-import-nav-step-completecentury-toolkit-import-step-contentcentury-toolkit-importer-form+11 moredata-century-toolkit-noncedata-ct-noncecentury_toolkit_data