
Extra Options For The Twenty Twenty Theme Security & Risk Analysis
wordpress.org/plugins/extra-options-for-twenty-twentyThis plugin lets you set a custom logo for Twenty Twenty WordPress theme's cover template, change the footer credits lines (copyright and powered …
Is Extra Options For The Twenty Twenty Theme Safe to Use in 2026?
Generally Safe
Score 85/100Extra Options For The Twenty Twenty Theme has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "extra-options-for-twenty-twenty" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. Furthermore, the code signals indicate a lack of dangerous functions, no file operations, and no external HTTP requests. The single SQL query uses prepared statements, and the majority of output is properly escaped.
However, there are a few areas for concern. The absence of nonce checks and capability checks across all entry points, while currently zero, presents a significant risk if any new entry points are introduced in the future without proper security controls. Similarly, the taint analysis showing zero flows is positive, but it's crucial to maintain this vigilance as the plugin evolves.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the positive static analysis, suggests a well-developed and maintained plugin. However, the lack of any recorded vulnerabilities does not guarantee future safety. The overall conclusion is that the plugin is currently secure, but a proactive approach to security, particularly regarding authentication and authorization for any future additions, is recommended.
Key Concerns
- No nonce checks
- No capability checks
- Minor output escaping concern (11% not properly escaped)
Extra Options For The Twenty Twenty Theme Security Vulnerabilities
Extra Options For The Twenty Twenty Theme Release Timeline
Extra Options For The Twenty Twenty Theme Code Analysis
SQL Query Safety
Output Escaping
Extra Options For The Twenty Twenty Theme Attack Surface
WordPress Hooks 16
Maintenance & Trust
Extra Options For The Twenty Twenty Theme Maintenance & Trust
Maintenance Signals
Community Trust
Extra Options For The Twenty Twenty Theme Alternatives
Login Logo
login-logo
Customize the logo on the WP login screen by simply dropping a file named login-logo.png into your WP content directory. CSS is automatic!
Change WordPress Login Logo
change-login-logo
Upload your logo for WordPress login page instead of the usual WordPress logo with simple settings.
My WordPress Login Logo
my-wp-login-logo
My WordPress Login Logo lets you to add a custom logo in your wordpress login page instead of the usual wordpress logo and customize your login page.
Add Logo to Admin
add-logo-to-admin
Add a custom logo to your wp-admin and login page.
Options for Twenty Twenty-One
options-for-twenty-twenty-one
Adds powerful customizer options to modify all aspects of the default WordPress theme Twenty Twenty-One.
Extra Options For The Twenty Twenty Theme Developer Profile
6 plugins · 2K total installs
How We Detect Extra Options For The Twenty Twenty Theme
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extra-options-for-twenty-twenty/css/extra-options-for-twenty-twenty.css/wp-content/plugins/extra-options-for-twenty-twenty/js/extra-options-for-twenty-twenty.js/wp-content/plugins/extra-options-for-twenty-twenty/js/extra-options-for-twenty-twenty.jsextra-options-for-twenty-twenty/css/extra-options-for-twenty-twenty.css?ver=extra-options-for-twenty-twenty/js/extra-options-for-twenty-twenty.js?ver=HTML / DOM Fingerprints
tteo2020-transparent-header-metatteo2020-transparent-header-input<!-- Transparent header<!-- Cover template logo --><!-- Footer credits --><!-- The theme has its own theme mods for footer -->+8 moredata-tteo2020-transparent-headertteo2020_transparent_header_opt