Core Framework Security & Risk Analysis

wordpress.org/plugins/core-framework

Say hello to Core Framework - a FREE modular CSS framework platform.

10K active installs v1.9.3 PHP 7.4+ WP 6.0+ Updated Jan 19, 2026
brickscssframeworkoxygenstylesheet
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Core Framework Safe to Use in 2026?

Generally Safe

Score 100/100

Core Framework has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The core-framework v1.9.3 plugin exhibits a generally strong security posture based on the static analysis. The absence of identified dangerous functions, the exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped output are all positive indicators. Furthermore, the plugin has no recorded vulnerabilities, including CVEs, suggesting a history of stable and secure development. The limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks, significantly reduces the potential for external exploitation.

Key Concerns

  • Zero nonce checks
  • Zero capability checks
  • Output escaping only 85% proper
Vulnerabilities
None known

Core Framework Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Core Framework Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
15 prepared
Unescaped Output
7
41 escaped
Nonce Checks
0
Capability Checks
0
File Operations
12
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared15 total queries

Output Escaping

85% escaped48 total outputs
Attack Surface

Core Framework Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionadmin_initcore-framework.php:57
actionplugins_loadedcore-framework.php:64
actionwp_initialize_sitecore-framework.php:75
actionadmin_noticescore-framework.php:76
actionadmin_headwp\App\Backend\Settings.php:89
actionwp_enqueue_scriptswp\App\Frontend\Enqueue.php:63
actionwp_enqueue_scriptswp\App\Frontend\Enqueue.php:71
actionwp_headwp\App\Frontend\Enqueue.php:75
actionwp_body_openwp\App\Frontend\Enqueue.php:82
actionwp_enqueue_scriptswp\App\Frontend\Enqueue.php:89
actionwp_footerwp\App\Frontend\Enqueue.php:90
actionwp_enqueue_scriptswp\App\Frontend\Enqueue.php:95
actionenqueue_block_editor_assetswp\App\Gutenberg\Functions.php:43
actionenqueue_block_assetswp\App\Gutenberg\Functions.php:44
actionenqueue_block_assetswp\App\Gutenberg\Functions.php:47
actionenqueue_block_assetswp\App\Gutenberg\Functions.php:48
filterwp_theme_json_data_themewp\App\Gutenberg\Functions.php:51
actionwp_enqueue_scriptswp\App\Gutenberg\Functions.php:52
actioninitwp\App\Gutenberg\Gutenberg.php:48
filterblock_categories_allwp\App\Gutenberg\Gutenberg.php:49
Maintenance & Trust

Core Framework Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 19, 2026
PHP min version7.4
Downloads142K

Community Trust

Rating100/100
Number of ratings41
Active installs10K
Developer Profile

Core Framework Developer Profile

Core Framework

1 plugin · 10K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Core Framework

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/core-framework/assets/public/css/backend.css/wp-content/plugins/core-framework/assets/public/js/backend.js
Script Paths
/wp-content/plugins/core-framework/assets/public/js/backend.js
Version Parameters
core-framework/assets/public/css/backend.css?ver=core-framework/assets/public/js/backend.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Core Framework has been installed. Please save changes in Core Framework plugin to update your stylesheet. -->
Data Attributes
data-cf-v
JS Globals
coreFramework
REST Endpoints
/wp-json/core-framework/v1
FAQ

Frequently Asked Questions about Core Framework