
Child Theme Wizard Security & Risk Analysis
wordpress.org/plugins/child-theme-wizardCreates a child theme with one click and lets you customise its options.
Is Child Theme Wizard Safe to Use in 2026?
Generally Safe
Score 85/100Child Theme Wizard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The child-theme-wizard plugin, version 1.4, exhibits a generally positive security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and importantly, all identified entry points appear to be protected. The plugin also demonstrates good practices by using prepared statements for all SQL queries, indicating a reduced risk of SQL injection vulnerabilities.
However, there are areas for concern. A significant portion of output (53%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted without adequate sanitization. Additionally, the taint analysis revealed two flows with unsanitized paths. While these are not classified as critical or high severity, the presence of unsanitized paths is a potential risk that could be exploited in combination with other weaknesses or if the plugin's functionality changes. The plugin's history of zero known CVEs is a strong positive, suggesting a well-maintained and secure codebase over time. Overall, the plugin has strengths in its limited attack surface and secure SQL handling, but the unescaped output and unsanitized paths warrant careful attention.
Key Concerns
- Unsanitized paths in taint analysis
- Significant portion of output not escaped
Child Theme Wizard Security Vulnerabilities
Child Theme Wizard Code Analysis
Output Escaping
Data Flow Analysis
Child Theme Wizard Attack Surface
WordPress Hooks 1
Maintenance & Trust
Child Theme Wizard Maintenance & Trust
Maintenance Signals
Community Trust
Child Theme Wizard Alternatives
Child Theme Creator by Orbisius
orbisius-child-theme-creator
Create Child Themes quickly and easily from any theme that you have currently installed on your site/blog.
ChildMaker AI
childmaker-ai
Create child themes quickly and easily from your WordPress admin panel — clean, simple, and safe.
MaxButtons – Create buttons
maxbuttons
Maxbuttons is the best and easiest button plugin for WordPress. Within minutes you can create beautiful buttons, share buttons and social icons.
WP Child Theme Generator
wp-child-theme-generator
WP Child Theme Generator is an easy solution to all your WordPress child theme creating problems!
Generate Child Theme
generate-child-theme
Create child themes of any WordPress themes effortlessly with Generate Child Theme.
Child Theme Wizard Developer Profile
4 plugins · 10K total installs
How We Detect Child Theme Wizard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/child-theme-wizard/images/guru-header-2013.pnghttps://apis.google.com/js/platform.jschild-theme-wizard/style.css?ver=child-theme-wizard/script.js?ver=HTML / DOM Fingerprints
wrapicon32errorupdateddata-channel="wphosting"gapi