Cryout Serious Theme Settings Security & Risk Analysis

wordpress.org/plugins/cryout-theme-settings

This plugin is designed to inter-operate with our Mantra, Parabola, Tempera, Nirvana themes to enable their settings pages.

40K active installs v0.5.17 PHP + WP 4.5+ Updated Jan 26, 2026
admintheme
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cryout Serious Theme Settings Safe to Use in 2026?

Generally Safe

Score 100/100

Cryout Serious Theme Settings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "cryout-theme-settings" v0.5.17 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified attack vectors such as AJAX handlers, REST API routes, or shortcodes without proper authentication or permission checks. The code also demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests. Crucially, all SQL queries are performed using prepared statements, and nonce and capability checks are present for all identified entry points. The absence of any recorded vulnerabilities in its history further supports this positive assessment.

However, a significant concern arises from the low percentage of properly escaped output (19%). This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. While the taint analysis shows no issues, this is likely due to the limited scope of the analysis or the specific coding patterns used, and the output escaping metric should not be overlooked. The plugin's strengths lie in its robust input validation and secure database interactions, but the lack of comprehensive output escaping is a notable weakness that warrants attention.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Cryout Serious Theme Settings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cryout Serious Theme Settings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
100
24 escaped
Nonce Checks
8
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

19% escaped124 total outputs
Attack Surface

Cryout Serious Theme Settings Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actioninitcryout-theme-settings.php:48
actionadmin_enqueue_scriptscryout-theme-settings.php:60
actionadmin_enqueue_scriptscryout-theme-settings.php:65
filterplugin_row_metacryout-theme-settings.php:77
actionadmin_menucryout-theme-settings.php:78
actionadmin_enqueue_scriptscryout-theme-settings.php:79
actionadmin_initincludes\mantra.php:6
actionmantra_before_rightyincludes\mantra.php:7
actionadmin_initincludes\mantra.php:74
actionmantra_after_rightyincludes\mantra.php:259
actionadmin_initincludes\nirvana.php:6
actionnirvana_before_rightyincludes\nirvana.php:7
actionadmin_initincludes\nirvana.php:80
actionnirvana_after_rightyincludes\nirvana.php:330
actionadmin_initincludes\parabola.php:6
actionparabola_before_rightyincludes\parabola.php:7
actionadmin_initincludes\parabola.php:80
actionparabola_after_rightyincludes\parabola.php:329
actionadmin_initincludes\tempera.php:6
actiontempera_before_rightyincludes\tempera.php:7
actionadmin_initincludes\tempera.php:72
actiontempera_after_rightyincludes\tempera.php:305
Maintenance & Trust

Cryout Serious Theme Settings Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 26, 2026
PHP min version
Downloads858K

Community Trust

Rating86/100
Number of ratings16
Active installs40K
Developer Profile

Cryout Serious Theme Settings Developer Profile

CryoutCreations

16 plugins · 121K total installs

79
trust score
Avg Security Score
87/100
Avg Patch Time
48 days
View full developer profile
Detection Fingerprints

How We Detect Cryout Serious Theme Settings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cryout-theme-settings/resources/code.js/wp-content/plugins/cryout-theme-settings/resources/style.css
Script Paths
resources/code.js
Version Parameters
cryout-theme-settings/resources/code.js?ver=cryout-theme-settings/resources/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
cryout-theme-settings-wrap
HTML Comments
<!-- * * * get things going * * * --><!-- EOF -->
Data Attributes
data-slugdata-version
FAQ

Frequently Asked Questions about Cryout Serious Theme Settings