Commandify — Admin Command Palette Security & Risk Analysis

wordpress.org/plugins/commandify

Commandify, a smart command palette for WordPress & WooCommerce. Instantly navigate, search, and manage admin tasks with fast keyboard commands.

10 active installs v1.0.7 PHP 7.4+ WP 6.2+ Updated Feb 4, 2026
instant-actionproductivityquick-navigationsearchspotlight-search
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Commandify — Admin Command Palette Safe to Use in 2026?

Generally Safe

Score 100/100

Commandify — Admin Command Palette has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the provided static analysis, commandify v1.0.7 exhibits a strong security posture. The plugin boasts a zero attack surface for direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events, with none of these being unprotected. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions identified, all SQL queries utilizing prepared statements, and a very high percentage of output being properly escaped. The presence of nonce and capability checks (37 and 3 respectively) indicates a good effort to secure functionalities.

Concerns are minimal given the data. The taint analysis showing zero flows, including those with unsanitized paths or critical/high severity, is excellent. The vulnerability history is also a significant strength, with no known CVEs at all, suggesting a history of secure development or effective patching. The only potential point of attention is the bundled Freemius library (v1.0), as outdated bundled libraries can sometimes present a risk if not actively maintained or if they contain known vulnerabilities not yet patched.

In conclusion, commandify v1.0.7 appears to be a secure plugin. Its lack of exploitable entry points, robust use of prepared statements and output escaping, and clean vulnerability history are all strong indicators of good security practices. The only minor deduction would be for the bundled Freemius library, which should be monitored for potential updates.

Key Concerns

  • Bundled Freemius v1.0 may be outdated
Vulnerabilities
None known

Commandify — Admin Command Palette Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Commandify — Admin Command Palette Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
109 escaped
Nonce Checks
3
Capability Checks
37
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

97% escaped112 total outputs
Attack Surface

Commandify — Admin Command Palette Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 33
filterpricing/show_annual_in_monthlycommandify.php:73
actionplugins_loadedcommandify.php:94
actionplugins_loadedcommandify.php:107
actionplugins_loadedcommandify.php:120
actionadmin_initcommandify.php:147
actionplugins_loadedcommandify.php:184
actionadmin_enqueue_scriptsincludes\Assets.php:10
actionadmin_footerincludes\Assets.php:11
actionwp_enqueue_scriptsincludes\Assets.php:14
actionwp_footerincludes\Assets.php:15
actionactivated_pluginincludes\Cache.php:9
actiondeactivated_pluginincludes\Cache.php:10
actionswitch_themeincludes\Cache.php:11
actioncommandify_register_commandsincludes\core-commands\action-commands.php:50
filtercommandify_execute_dynamic_actionincludes\core-commands\action-commands.php:519
actioncommandify_register_commandsincludes\core-commands\installation-commands.php:47
actionadmin_menuincludes\core-commands\navigation-commands.php:140
actioncommandify_register_commandsincludes\core-commands\navigation-commands.php:341
actionadmin_menuincludes\core-commands\navigation-commands.php:345
actioncommandify_register_commandsincludes\core-commands\plugin-theme-commands.php:48
actioncommandify_register_commandsincludes\core-commands\search-commands.php:71
filtercommandify_post_actionsincludes\integrations\elementor.php:46
filtercommandify_navigation_command_iconincludes\integrations\elementor.php:52
actioncommandify_register_frontend_contextual_commandsincludes\integrations\elementor.php:134
actioninitincludes\integrations\elementor.php:215
actioninitincludes\Registry.php:20
actionrest_api_initincludes\RestApi.php:11
actionadmin_menuincludes\Settings.php:21
actionadmin_initincludes\Settings.php:22
actionshow_user_profileincludes\Settings.php:25
actionedit_user_profileincludes\Settings.php:26
actionpersonal_options_updateincludes\Settings.php:27
actionedit_user_profile_updateincludes\Settings.php:28
Maintenance & Trust

Commandify — Admin Command Palette Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 4, 2026
PHP min version7.4
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Commandify — Admin Command Palette Developer Profile

wpRigel

2 plugins · 70 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Commandify — Admin Command Palette

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/commandify/assets/build/index.css/wp-content/plugins/commandify/assets/build/index.js
Script Paths
/wp-content/plugins/commandify/assets/build/index.asset.php
Version Parameters
commandify/assets/build/index.css?ver=commandify/assets/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
commandify-modalcommandify-inputcommandify-command-listcommandify-group-header
HTML Comments
Commandify: Command PaletteCommandify: Search InputCommandify: Command ListCommandify: Group Header
Data Attributes
data-commandify-appdata-commandify-modal-iddata-commandify-item-id
JS Globals
window.Commandify
REST Endpoints
/wp-json/commandify/v1/commands
FAQ

Frequently Asked Questions about Commandify — Admin Command Palette