
Ceylon Extra Security & Risk Analysis
wordpress.org/plugins/ecommerce-extraEnhances eCommerce Plus theme with additional functionality such as customizer and widgets.
Is Ceylon Extra Safe to Use in 2026?
Generally Safe
Score 85/100Ceylon Extra has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ecommerce-extra" plugin v0.0.6 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the exclusive use of prepared statements for SQL queries are excellent indicators of secure coding practices. Furthermore, the high percentage of properly escaped output suggests a good effort to prevent cross-site scripting vulnerabilities. The plugin also appears to have a minimal attack surface, with no discoverable AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication or capability checks. The clean vulnerability history, with zero known CVEs, further bolsters confidence in its security. However, the complete lack of nonce checks and capability checks across all entry points is a significant concern. While the current attack surface is zero, this absence creates a latent risk if new entry points are introduced in the future without these essential security measures. This could leave the plugin vulnerable to CSRF and privilege escalation attacks. The plugin's current security is commendable, but the lack of these fundamental checks represents a critical oversight that needs immediate attention to ensure future resilience.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
Ceylon Extra Security Vulnerabilities
Ceylon Extra Code Analysis
Output Escaping
Ceylon Extra Attack Surface
WordPress Hooks 12
Maintenance & Trust
Ceylon Extra Maintenance & Trust
Maintenance Signals
Community Trust
Ceylon Extra Alternatives
Ultimate Addons for SiteOrigin
addon-so-widgets-bundle
An ultimate collection of addons for SiteOrigin. SiteOrigin Widgets Bundle is required.
WP Bootstrap Widgets
wp-bootstrap-widgets
WP Bootstrap Widgets provides configurable widgets for common Twitter Bootstrap (version 3) components. If your theme is based on Bootstrap, these wid …
Massive Visual Page Builder
massive-visual-builder-page-layout-builder
theme builder, squeeze page builder, sales page builder, drag and drop page builder, drag and drop content builder, drag drop Requires at least: 3.
Page Builder by SiteOrigin
siteorigin-panels
Build responsive page layouts using the widgets you know and love using this simple drag and drop page builder.
Elementor Custom Skin
ele-custom-skin
Create new skins for Elementor PRO 3.x page builder. Design your own skins for Post and Post Archive Widgets using Elementor Loop Templates.
Ceylon Extra Developer Profile
3 plugins · 2K total installs
How We Detect Ceylon Extra
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ecommerce-extra/style.css/wp-content/plugins/ecommerce-extra/fonts/font-awesome/css/font-awesome.min.css/wp-content/plugins/ecommerce-extra/inc/customizer-repeater/css/admin-style.css/wp-content/plugins/ecommerce-extra/inc/customizer-repeater/js/customizer_repeater.js/wp-content/plugins/ecommerce-extra/inc/customizer-repeater/js/fontawesome-iconpicker.js/wp-content/plugins/ecommerce-extra/inc/customizer-repeater/css/fontawesome-iconpicker.min.css/wp-content/plugins/ecommerce-extra/inc/customizer-repeater/js/customizer_repeater.js/wp-content/plugins/ecommerce-extra/inc/customizer-repeater/js/fontawesome-iconpicker.jsecommerce-extra/style.css?ver=ecommerce-extra/fonts/font-awesome/css/font-awesome.min.css?ver=ecommerce-extra/inc/customizer-repeater/css/admin-style.css?ver=ecommerce-extra/inc/customizer-repeater/js/customizer_repeater.js?ver=ecommerce-extra/inc/customizer-repeater/js/fontawesome-iconpicker.js?ver=ecommerce-extra/inc/customizer-repeater/css/fontawesome-iconpicker.min.css?ver=HTML / DOM Fingerprints
customizer-repeater-general-control-repeatercustomizer-repeater-general-control-droppablecustomizer-repeater-colectordata-elementor-iddata-elementor-typeecommerce_extra_dir_uri