
CWW Companion Security & Risk Analysis
wordpress.org/plugins/cww-companionThis plugin adds some useful featuers to themes made by us(Code Work Web).
Is CWW Companion Safe to Use in 2026?
Generally Safe
Score 98/100CWW Companion has a strong security track record. Known vulnerabilities have been patched promptly.
The "cww-companion" plugin v1.3.7 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, ensuring no REST API routes or shortcodes are exposed without proper checks, and implementing a significant number of nonce and capability checks. The absence of critical or high-severity taint analysis findings, unsanitized paths, and unpatched CVEs is also reassuring. However, the presence of the `unserialize` function is a notable concern, as it can be a vector for remote code execution if not handled with extreme caution and input validation. Furthermore, the relatively low percentage of properly escaped output (77%) suggests a potential for cross-site scripting (XSS) vulnerabilities, especially given the plugin's history of such issues.
Key Concerns
- Presence of 'unserialize' function
- Suboptimal output escaping percentage
- Past vulnerabilities in XSS and CSRF
CWW Companion Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
CWW Companion <= 1.3.2 - Cross-Site Request Forgery
CWW Companion <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
CWW Companion Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
CWW Companion Attack Surface
AJAX Handlers 9
WordPress Hooks 33
Maintenance & Trust
CWW Companion Maintenance & Trust
Maintenance Signals
Community Trust
CWW Companion Alternatives
Beastthemes Companion
beastthemes-companion
The beastthemes companion plugin adds extra functionality to the themes of beastthemes.
Steed Companion
steed-companion
Enhances Steed’s themes with extra functionalities.
Child Theme Configurator
child-theme-configurator
When using the Customizer is not enough - Create a child theme from your installed themes and customize styles, templates, functions and more.
Hello Plus
hello-plus
Hello+ is a free WordPress plugin designed to work seamlessly with Elementor’s Hello suite of themes.
Mesmerize Companion
mesmerize-companion
The Mesmerize Companion plugin adds drag and drop page builder functionality to the Mesmerize theme.
CWW Companion Developer Profile
12 plugins · 7K total installs
How We Detect CWW Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cww-companion/inc/assets/css/common.css/wp-content/plugins/cww-companion/inc/assets/css/customizer.css/wp-content/plugins/cww-companion/inc/assets/js/main.js/wp-content/plugins/cww-companion/inc/assets/js/customizer.js/wp-content/plugins/cww-companion/inc/assets/js/customizer-preview.js/wp-content/plugins/cww-companion/inc/assets/js/elementor-widget.js/wp-content/plugins/cww-companion/inc/assets/js/main.js/wp-content/plugins/cww-companion/inc/assets/js/customizer.js/wp-content/plugins/cww-companion/inc/assets/js/customizer-preview.js/wp-content/plugins/cww-companion/inc/assets/js/elementor-widget.jscww-companion/inc/assets/css/common.css?ver=cww-companion/inc/assets/css/customizer.css?ver=cww-companion/inc/assets/js/main.js?ver=cww-companion/inc/assets/js/customizer.js?ver=cww-companion/inc/assets/js/customizer-preview.js?ver=cww-companion/inc/assets/js/elementor-widget.js?ver=HTML / DOM Fingerprints
cww-companion-logocww-companion-theme-supportcww-companion-demo-import-buttondata-cww-plugin-settingscww_companion_params/wp-json/cww-companion/v1/settings[cww_companion_shortcode]