
Child Themify Security & Risk Analysis
wordpress.org/plugins/child-themifyCreate child themes with the click of a button.
Is Child Themify Safe to Use in 2026?
Generally Safe
Score 85/100Child Themify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The child-themify plugin v2.0.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs, critical taint flows, dangerous functions, and SQL injection vulnerabilities using prepared statements are positive indicators. Furthermore, the limited attack surface, with all entry points having permission callbacks and the presence of capability checks, suggests good security practices in place for handling user interactions and administrative functions.
However, a significant concern arises from the output escaping analysis, where 100% of the outputs are not properly escaped. This presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. While the plugin has no recorded vulnerability history, this single weakness in output handling can be exploited to compromise the security of the site and its users. The presence of file operations, while not inherently insecure, warrants careful review in conjunction with the unescaped output to ensure no sensitive files are inadvertently exposed or manipulated.
In conclusion, while the plugin demonstrates strengths in preventing common vulnerabilities like SQL injection and controlling its attack surface, the lack of output escaping is a critical flaw that needs immediate attention. The plugin's clean vulnerability history is commendable, but it does not negate the current high risk introduced by the unescaped output. Addressing this output escaping issue should be the top priority to mitigate the risk of XSS attacks.
Key Concerns
- 100% of outputs not properly escaped
Child Themify Security Vulnerabilities
Child Themify Code Analysis
Output Escaping
Child Themify Attack Surface
REST API Routes 2
WordPress Hooks 2
Maintenance & Trust
Child Themify Maintenance & Trust
Maintenance Signals
Community Trust
Child Themify Alternatives
Child Theme Configurator
child-theme-configurator
When using the Customizer is not enough - Create a child theme from your installed themes and customize styles, templates, functions and more.
Child Theme Creator by Orbisius
orbisius-child-theme-creator
Create Child Themes quickly and easily from any theme that you have currently installed on your site/blog.
Childify Me
childify-me
Create a child-theme from the Theme Customizer.
Child Themes
child-themes
Create a child theme really easily from any installed theme.
BNS Theme Add-Ins
bns-theme-add-ins
Extend the capabilities of WordPress Parent-Themes and Child-Themes
Child Themify Developer Profile
2 plugins · 7K total installs
How We Detect Child Themify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/child-themify/assets/css/child-themify-admin.css/wp-content/plugins/child-themify/assets/js/child-themify-admin.jschild-themify/assets/css/child-themify-admin.css?ver=child-themify/assets/js/child-themify-admin.js?ver=HTML / DOM Fingerprints
ctfAppRootdata-resturldata-noncedata-themesdata-current-userdata-i18nChildThemify/wp-json/child-themify/v1/theme-data//wp-json/child-themify/v1/create-theme