
Cornerstone Security & Risk Analysis
wordpress.org/plugins/cornerstoneEnhanced content management for WordPress
Is Cornerstone Safe to Use in 2026?
Use With Caution
Score 67/100Cornerstone has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin "cornerstone" v0.8.1 presents a mixed security posture. While the attack surface appears to be minimal with no identified AJAX handlers, REST API routes, shortcodes, or cron events, the code signals reveal significant concerns. The presence of "create_function", a dangerous PHP function known for potential security risks, is a notable weakness. Furthermore, a concerning 58% of output escaping is not properly implemented, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also shows that 60% of analyzed flows have unsanitized paths, though no critical or high-severity issues were found in this specific analysis.
The vulnerability history is a major red flag, with three known CVEs, one of which remains unpatched. The common vulnerability type being Cross-Site Scripting aligns with the output escaping findings. The fact that the last vulnerability was recent (2025-10-06) suggests ongoing security challenges with this plugin. While the plugin exhibits some good practices like a high percentage of prepared SQL statements and some capability checks, the combination of dangerous functions, insufficient output escaping, unsanitized paths, and a history of unpatched XSS vulnerabilities points to a plugin that requires significant attention to security.
In conclusion, the "cornerstone" v0.8.1 plugin has fundamental security weaknesses in its code that, coupled with its vulnerability history, create a substantial risk. The lack of proper output escaping is a critical vulnerability that could be exploited by attackers. The presence of dangerous functions and unpatched vulnerabilities further exacerbates the risk. Users should exercise extreme caution and prioritize updating or seeking alternative solutions.
Key Concerns
- Unpatched CVE detected
- Dangerous function detected (create_function)
- High percentage of unescaped output
- Flows with unsanitized paths detected
- Multiple past vulnerabilities (3 total)
Cornerstone Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Cornerstone <= 7.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Cornerstone <= 0.8.0 - Reflected Cross-Site Scripting
Cornerstone <= 0.8.0 - Reflected Cross-Site Scripting via PHP_SELF
Cornerstone Release Timeline
Cornerstone Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Cornerstone Attack Surface
WordPress Hooks 40
Maintenance & Trust
Cornerstone Maintenance & Trust
Maintenance Signals
Community Trust
Cornerstone Alternatives
Clicface Organi
clicface-organi
Create Org Charts easily in WordPress. A flexible and lightweight WordPress plugin, working with Clicface Trombi.
TalentLMS WordPress plugin
talentlms
This plugin integrates Talentlms with Wordpress. Promote your TalentLMS content through your WordPress site.
Simple Page Folder Organizer
simple-page-folder-organizer
Organize WordPress pages into folders for better backend management.
SYSSY – Monitoring Websites
syssy
Connects your WordPress website with SYSSY for monitoring and security issue reporting. Requires account on https://www.syssy.net.
SEO Schema – Structured Data & Breadcrumb List
seo-schema-structured-data-breadcrumb-list
A WordPress plugin to add structured data for Organization Schema and Breadcrumb Schema using JSON-LD.
Cornerstone Developer Profile
4 plugins · 150K total installs
How We Detect Cornerstone
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cornerstone/assets/css/main.css/wp-content/plugins/cornerstone/assets/js/main.jscornerstone/assets/css/main.css?ver=cornerstone/assets/js/main.js?ver=HTML / DOM Fingerprints
cnr-wrappercnr-bodycnr-contentcnr-sidebarcnr-footercnr-headercnr-navcnr-menu+43 moredata-cnrdata-cnr-iddata-cnr-typedata-cnr-valuedata-cnr-optionsCNRcnr