Custom Sidebars by ProteusThemes Security & Risk Analysis

wordpress.org/plugins/custom-sidebars-by-proteusthemes

Allows you to create custom sidebars. Replace sidebars for specific posts and pages.

1K active installs v1.0.3 PHP + WP 5.2+ Updated Sep 19, 2022
customcustom-sidebarssidebarsidebarswidgets
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEDec 4, 2025
Safety Verdict

Is Custom Sidebars by ProteusThemes Safe to Use in 2026?

Use With Caution

Score 63/100

Custom Sidebars by ProteusThemes has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Dec 4, 2025Updated 3yr ago
Risk Assessment

The plugin "custom-sidebars-by-proteusthemes" v1.0.3 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators. The high percentage of properly escaped output further contributes to its strength. However, the zero nonce checks are a significant concern, especially given the presence of an AJAX handler. This lack of protection on the single entry point creates a potential for cross-site request forgery attacks.

The vulnerability history reveals a known medium severity CVE, which is currently unpatched. While the specific type of CSRF suggests a pattern, the fact that it remains unpatched is a serious drawback. The static analysis did not reveal any critical or high severity taint flows, which is positive, but the presence of an AJAX handler without a nonce check, combined with the unpatched CVE, elevates the overall risk.

In conclusion, while the plugin demonstrates strong development practices in many areas, the combination of an unpatched CVE and the absence of nonce checks on its sole AJAX handler presents a notable security risk. Addressing the unpatched vulnerability and implementing nonce checks on the AJAX handler are critical steps to improve the plugin's security.

Key Concerns

  • Unpatched medium severity CVE
  • Missing nonce check on AJAX handler
  • Less than 100% output escaping
Vulnerabilities
1

Custom Sidebars by ProteusThemes Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62733medium · 4.3Cross-Site Request Forgery (CSRF)

Custom Sidebars by ProteusThemes <= 1.0.3 - Cross-Site Request Forgery

Dec 4, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Custom Sidebars by ProteusThemes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
20 escaped
Nonce Checks
0
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped22 total outputs
Attack Surface

Custom Sidebars by ProteusThemes Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_cs-ajaxinc\class-pt-cs-main.php:69
WordPress Hooks 17
actionplugins_loadedcustom-sidebars-by-proteusthemes.php:67
actionadmin_noticescustom-sidebars-by-proteusthemes.php:96
actionplugins_loadedcustom-sidebars-by-proteusthemes.php:102
actionpt-cs/initinc\class-pt-cs-editor.php:9
actionadd_meta_boxesinc\class-pt-cs-editor.php:43
actionsave_postinc\class-pt-cs-editor.php:46
actionpt-cs/ajax_requestinc\class-pt-cs-editor.php:49
actionadmin_noticesinc\class-pt-cs-main.php:63
actionadmin_enqueue_scriptsinc\class-pt-cs-main.php:66
actionpt-cs/initinc\class-pt-cs-replacer.php:9
actionwidgets_initinc\class-pt-cs-replacer.php:43
actionwp_headinc\class-pt-cs-replacer.php:47
actionwpinc\class-pt-cs-replacer.php:48
actionpt-cs/initinc\class-pt-cs-widgets.php:9
actionwidgets_admin_pageinc\class-pt-cs-widgets.php:43
actionadmin_head-widgets.phpinc\class-pt-cs-widgets.php:44
filteradmin_body_classinc\class-pt-cs-widgets.php:61
Maintenance & Trust

Custom Sidebars by ProteusThemes Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 19, 2022
PHP min version
Downloads22K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

Custom Sidebars by ProteusThemes Developer Profile

ProteusThemes

3 plugins · 5K total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Sidebars by ProteusThemes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-sidebars-by-proteusthemes/assets/css/main.min.css/wp-content/plugins/custom-sidebars-by-proteusthemes/assets/js/main.min.js/wp-content/plugins/custom-sidebars-by-proteusthemes/bower_components/tinyscrollbar/lib/jquery.tinyscrollbar.min.js
Script Paths
/wp-content/plugins/custom-sidebars-by-proteusthemes/assets/js/main.min.js/wp-content/plugins/custom-sidebars-by-proteusthemes/bower_components/tinyscrollbar/lib/jquery.tinyscrollbar.min.js
Version Parameters
custom-sidebars-by-proteusthemes/assets/css/main.min.css?ver=custom-sidebars-by-proteusthemes/assets/js/main.min.js?ver=custom-sidebars-by-proteusthemes/bower_components/tinyscrollbar/lib/jquery.tinyscrollbar.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
pt-cs-main-js
JS Globals
PT_CS_VERSION
FAQ

Frequently Asked Questions about Custom Sidebars by ProteusThemes