
Custom X Pro Elements by Hexio Security & Risk Analysis
wordpress.org/plugins/custom-x-pro-elementsCustom X Pro Elements is a package of custom elements to use with Themeco's X Pro theme
Is Custom X Pro Elements by Hexio Safe to Use in 2026?
Generally Safe
Score 85/100Custom X Pro Elements by Hexio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'custom-x-pro-elements' plugin v1.0.2 exhibits a strong security posture in several key areas, with no reported vulnerabilities or identified critical taint flows. The absence of dangerous functions, file operations, and external HTTP requests is commendable. All SQL queries are correctly prepared, mitigating the risk of SQL injection. However, a significant concern arises from the complete lack of output escaping on all identified outputs. This represents a critical flaw, as any dynamic content rendered without proper escaping is vulnerable to Cross-Site Scripting (XSS) attacks. Despite the plugin's clean history and lack of direct attack surface, the unescaped output introduces a substantial risk that cannot be overlooked. While the plugin has good foundational security practices, the output escaping deficiency demands immediate attention.
Key Concerns
- All outputs lack proper escaping
Custom X Pro Elements by Hexio Security Vulnerabilities
Custom X Pro Elements by Hexio Release Timeline
Custom X Pro Elements by Hexio Code Analysis
Output Escaping
Custom X Pro Elements by Hexio Attack Surface
WordPress Hooks 3
Maintenance & Trust
Custom X Pro Elements by Hexio Maintenance & Trust
Maintenance Signals
Community Trust
Custom X Pro Elements by Hexio Alternatives
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Solid Security – Password, Two Factor Authentication, and Brute Force Protection
better-wp-security
Harden your site security with Login Security, Two-Factor Authentication (2FA), Vulnerability Scanner, Firewall, and more. Formerly iThemes Security.
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Addons for Contact Form 7 — Honeypot, Database Entries, Redirection, Spam Protection, Webhooks, ACF integration for Contact Form 7, and more.
Custom X Pro Elements by Hexio Developer Profile
1 plugin · 0 total installs
How We Detect Custom X Pro Elements by Hexio
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.