
Child Themes Security & Risk Analysis
wordpress.org/plugins/child-themesCreate a child theme really easily from any installed theme.
Is Child Themes Safe to Use in 2026?
Use With Caution
Score 63/100Child Themes has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'child-themes' plugin v1.0.1 exhibits a concerning security posture, despite some positive indicators. While the static analysis shows a seemingly small attack surface and no dangerous functions, the output escaping is alarmingly low at only 4%. This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, where unsanitized user input could be rendered directly in the browser. Furthermore, the taint analysis reveals three flows with unsanitized paths, which, while not classified as critical or high severity in this report, still represent potential security weaknesses that could be exploited. The presence of one known, unpatched CVE, specifically a medium severity XSS vulnerability, is a significant red flag and points to a history of security issues within this plugin. The fact that the last vulnerability was very recent (2025-08-21) further emphasizes the ongoing risk. The lack of capability checks and nonce checks on any entry points, combined with the low output escaping rate and the unpatched CVE, suggests a plugin that is not adhering to robust WordPress security best practices, leaving it vulnerable to potentially serious attacks.
Key Concerns
- Unescaped output (96% unescaped)
- Flows with unsanitized paths (3)
- Unpatched CVE (1 medium)
- Missing nonce checks
- Missing capability checks
Child Themes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Child Themes <= 1.0.1 - Reflected Cross-Site Scripting
Child Themes Code Analysis
Output Escaping
Data Flow Analysis
Child Themes Attack Surface
WordPress Hooks 2
Maintenance & Trust
Child Themes Maintenance & Trust
Maintenance Signals
Community Trust
Child Themes Alternatives
Child Theme Configurator
child-theme-configurator
When using the Customizer is not enough - Create a child theme from your installed themes and customize styles, templates, functions and more.
Child Theme Creator by Orbisius
orbisius-child-theme-creator
Create Child Themes quickly and easily from any theme that you have currently installed on your site/blog.
Childify Me
childify-me
Create a child-theme from the Theme Customizer.
Child Themify
child-themify
Create child themes with the click of a button.
BNS Theme Add-Ins
bns-theme-add-ins
Extend the capabilities of WordPress Parent-Themes and Child-Themes
Child Themes Developer Profile
11 plugins · 460 total installs
How We Detect Child Themes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
childthemes