
Extendify Security & Risk Analysis
wordpress.org/plugins/extendifyThe best WordPress templates, pattern, and layout library with 1,000+ designs built for the Gutenberg block editor.
Is Extendify Safe to Use in 2026?
Generally Safe
Score 100/100Extendify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The extendify plugin v2.4.1 demonstrates a generally strong security posture based on the provided static analysis. The complete absence of unescaped output and the significant percentage of SQL queries utilizing prepared statements are excellent indicators of secure coding practices. The plugin also correctly avoids dangerous functions and appears to have limited file operations and external HTTP requests, further reducing its potential attack surface.
However, a notable concern arises from the complete lack of nonce checks. While the static analysis did not identify any direct AJAX handlers or REST API routes without authentication, the absence of nonce checks is a critical oversight. This leaves any potential future endpoints, or even current ones that might have been missed in the analysis, vulnerable to Cross-Site Request Forgery (CSRF) attacks. The plugin also has only two capability checks, which might indicate insufficient authorization controls for certain functionalities, although without knowing the specific functions, this is a less certain deduction.
The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This suggests a history of responsible development and security awareness. In conclusion, extendify v2.4.1 is well-developed with strong output escaping and data sanitization practices, but the complete lack of nonce checks presents a significant, albeit potentially latent, security risk that needs immediate attention.
Key Concerns
- Missing nonce checks on all entry points
- Limited capability checks (2 total)
Extendify Security Vulnerabilities
Extendify Code Analysis
SQL Query Safety
Output Escaping
Extendify Attack Surface
WordPress Hooks 18
Scheduled Events 2
Maintenance & Trust
Extendify Maintenance & Trust
Maintenance Signals
Community Trust
Extendify Alternatives
Qi Blocks
qi-blocks
Qi Blocks is the largest collection of Gutenberg blocks developed by Qode Interactive.
PatternsWP – Gutenberg Block Patterns & Page Templates Library
patternswp
Explore a library of pre-designed Gutenberg block patterns and page templates that are compatible with any WordPress block theme.
Timeline Blocks for Gutenberg
timeline-blocks
A beautiful timeline layout block to showcase your posts in timeline presentation.
Rocksite Kit – Kadence Blocks Patterns with Figma UI Kit
rocksite-sections
Collection of ready-to-use Gutenberg sections (block patterns) based on Kadence Blocks Library: Hero Sections, Features Sections, Call to Actions etc.
Patterns Store – Creates a store to manage and display patterns & pattern kits
patterns-store
Create a store to manage and display patterns, pattern kits, and theme JSON packages. Perfect for designers and developers.
Extendify Developer Profile
2 plugins · 700K total installs
How We Detect Extendify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extendify/public/build/extendify-agent.css/wp-content/plugins/extendify/public/build/extendify-agent.js/wp-content/plugins/extendify/public/build/extendify-shared.css/wp-content/plugins/extendify/public/build/extendify-shared.js/wp-content/plugins/extendify/vendor/wp-extendify/wp-extendify-core/resources/css/inline.csswp-content/plugins/extendify/public/build/extendify-agent.jswp-content/plugins/extendify/public/build/extendify-shared.jsextendify/style.css?ver=extendify/script.js?ver=HTML / DOM Fingerprints
extendify-agent-chatextendify-assistextendify-tourextendify-workflow-historywp-extendify-core<!-- Extendify Assist --><!-- Extendify Tour --><!-- Extendify Workflow History -->data-extendify-chat-targetdata-extendify-tour-targetdata-extendify-workflow-history-targetextendifyEXTENDIFY_BASE_URLEXTENDIFY_DEVMODEEXTENDIFY_PARTNER_ID/wp-json/extendify/v1/chat/wp-json/extendify/v1/tour/wp-json/extendify/v1/workflow-history[extendify_chat][extendify_tour][extendify_workflow_history]