
Envo Companion Security & Risk Analysis
wordpress.org/plugins/envo-companionEnvo Companion is a companion plugin for Webenvo themes.
Is Envo Companion Safe to Use in 2026?
Generally Safe
Score 100/100Envo Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of envo-companion v0.0.7 reveals a generally strong security posture. The plugin demonstrates excellent adherence to secure coding practices, with no identified dangerous functions, file operations, or external HTTP requests. Crucially, all SQL queries are properly prepared, and a very high percentage of output is correctly escaped, significantly mitigating risks of SQL injection and cross-site scripting (XSS). The absence of any recorded vulnerabilities, including CVEs of any severity, further supports this positive assessment. The plugin also appears to have a minimal attack surface with no identifiable entry points like AJAX handlers, REST API routes, or shortcodes, and importantly, no untainted taint flows were detected. The lack of nonce checks and capability checks on the identified entry points (albeit zero) is a minor concern, but given the complete absence of these entry points in this version, the immediate risk is negligible. Overall, the plugin is well-coded from a security perspective, with its primary strengths being robust output escaping, secure SQL practices, and a clean vulnerability history. The lack of any discovered entry points is a significant positive, but the oversight in capability checks on the *potential* for entry points, however small, could be a future risk if functionality is added without proper security considerations.
Key Concerns
- No capability checks on entry points
- No nonce checks on entry points
Envo Companion Security Vulnerabilities
Envo Companion Code Analysis
Output Escaping
Envo Companion Attack Surface
WordPress Hooks 8
Maintenance & Trust
Envo Companion Maintenance & Trust
Maintenance Signals
Community Trust
Envo Companion Alternatives
WPFrank Companion
wpfrank-companion
WPFrank Companion is a companion plugin for WP Frank themes.
Avantex Companion
avantex-companion
tested up to 6.8 License: GPLv3 or later License URI: http://www.gnu.org/licenses/gpl-3.0.html Avantex Companion is a companion plugin for Avantex the …
Marin Companion
marin-companion
Marin Companion is a companion plugin for Marin theme.
Daddy Plus
daddy-plus
Daddy Plus is a useful plugin for WordPress theme by Themes Daddy.
Desert Companion
desert-companion
Desert Companion Enhances Desert Themes with additional functionality.
Envo Companion Developer Profile
61 plugins · 64K total installs
How We Detect Envo Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/envo-companion/inc/webenvo/demo-content/webenvo/webenvo.xml/wp-content/plugins/envo-companion/inc/webenvo/demo-content/webenvo/webenvo.wie/wp-content/plugins/envo-companion/inc/webenvo/demo-content/webenvo/webenvo.dat/wp-content/plugins/envo-companion/inc/webenvo/img/demo-screenshots/webenvo.png/wp-content/plugins/envo-companion/inc/webenvo/img/demo-screenshots/webenvo-pro.webpHTML / DOM Fingerprints
webenvo-starter-sitesocdi__gl-itemocdi__gl-item-buttonsocdi__theme-aboutocdi__intro-textocdi__gl-item-image-containerwebenvo-starter-sites-admin-page<!-- Plugin Name: Envo Companion --><!-- Plugin URI: https://wordpress.org/plugins/envo-companion --><!-- Description: Envo Companion plugin provides themes extra settings for theme envo. --><!-- Version: 0.0.7 -->+34 more