Custom Welcome Guide Security & Risk Analysis

wordpress.org/plugins/custom-welcome-guide

Easily add step-by-step tours/tutorials/walkthrough guides that get displayed in the WordPress admin. Replace the default welcome guide modal dialog i …

10 active installs v1.0.9 PHP 5.6+ WP 5.4+ Updated Dec 19, 2024
block-editorintroductiontouruser-onboardingwalkthrough
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Custom Welcome Guide Safe to Use in 2026?

Generally Safe

Score 92/100

Custom Welcome Guide has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of the 'custom-welcome-guide' plugin v1.0.9 reveals an exceptionally clean codebase from a security perspective. There are no identified AJAX handlers, REST API routes, shortcodes, cron events, or file operations, meaning the attack surface is effectively zero. Furthermore, the code demonstrates strong security practices with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. Taint analysis found no concerning flows, and the plugin has no history of known vulnerabilities.

This indicates a plugin that has been developed with security as a high priority. The lack of any exploitable entry points and the adherence to secure coding standards are commendable. However, the complete absence of nonce checks and capability checks across all potential, albeit nonexistent, entry points is a notable omission. While not a direct risk given the current lack of attack surface, it suggests a potential gap in secure development practices that could become a concern if the plugin's functionality were to expand in the future.

In conclusion, 'custom-welcome-guide' v1.0.9 currently presents a very low-risk profile due to its minimal attack surface and robust adherence to secure coding principles. The absence of vulnerabilities and secure data handling are significant strengths. The primary area for potential improvement lies in the implementation of capability checks and nonces, which would further harden the plugin against future threats, even in the absence of current attack vectors.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Custom Welcome Guide Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Custom Welcome Guide Release Timeline

v1.0.9Current
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Custom Welcome Guide Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

Custom Welcome Guide Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitinc\guide.php:49
actioninitindex.php:45
actionenqueue_block_editor_assetsindex.php:56
actionadmin_enqueue_scriptsindex.php:72
actionadmin_noticesindex.php:89
actionadmin_menuindex.php:107
actionrest_api_initindex.php:159
actioninitindex.php:225
actionadmin_headindex.php:259
Maintenance & Trust

Custom Welcome Guide Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 19, 2024
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Custom Welcome Guide Developer Profile

Atanas Yonkov

19 plugins · 13K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Custom Welcome Guide

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-welcome-guide/build/index.js/wp-content/plugins/custom-welcome-guide/build/style-index.css/wp-content/plugins/custom-welcome-guide/build/admin.js/wp-content/plugins/custom-welcome-guide/build/admin.css
Script Paths
/wp-content/plugins/custom-welcome-guide/build/index.js/wp-content/plugins/custom-welcome-guide/build/admin.js
Version Parameters
custom-welcome-guide/build/style-index.css?ver=custom-welcome-guide/build/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
custom-welcome-guide-wrapper
Data Attributes
id="custom-welcome-guide-wrapper"
JS Globals
custom_welcome_guide_script_params
REST Endpoints
/wp-json/wp/v2/guides
FAQ

Frequently Asked Questions about Custom Welcome Guide