Extra Options For The Twenty Twenty Theme Security & Risk Analysis

wordpress.org/plugins/extra-options-for-twenty-twenty

This plugin lets you set a custom logo for Twenty Twenty WordPress theme's cover template, change the footer credits lines (copyright and powered …

100 active installs v1.0.0 PHP 5.5+ WP 5.0.0+ Updated Dec 13, 2019
cover-templatecustom-logoremove-copyrighttransparent-headertwenty-twenty
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Extra Options For The Twenty Twenty Theme Safe to Use in 2026?

Generally Safe

Score 85/100

Extra Options For The Twenty Twenty Theme has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "extra-options-for-twenty-twenty" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. Furthermore, the code signals indicate a lack of dangerous functions, no file operations, and no external HTTP requests. The single SQL query uses prepared statements, and the majority of output is properly escaped.

However, there are a few areas for concern. The absence of nonce checks and capability checks across all entry points, while currently zero, presents a significant risk if any new entry points are introduced in the future without proper security controls. Similarly, the taint analysis showing zero flows is positive, but it's crucial to maintain this vigilance as the plugin evolves.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the positive static analysis, suggests a well-developed and maintained plugin. However, the lack of any recorded vulnerabilities does not guarantee future safety. The overall conclusion is that the plugin is currently secure, but a proactive approach to security, particularly regarding authentication and authorization for any future additions, is recommended.

Key Concerns

  • No nonce checks
  • No capability checks
  • Minor output escaping concern (11% not properly escaped)
Vulnerabilities
None known

Extra Options For The Twenty Twenty Theme Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Extra Options For The Twenty Twenty Theme Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 16, 2026

Extra Options For The Twenty Twenty Theme Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
1
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

89% escaped9 total outputs
Attack Surface

Extra Options For The Twenty Twenty Theme Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_menuextra-options-for-twenty-twenty.php:34
actionactivated_pluginextra-options-for-twenty-twenty.php:90
actionplugins_loadedextra-options-for-twenty-twenty.php:100
filtertheme_mod_custom_logoextra-options-for-twenty-twenty.php:147
actionwp_loadedextra-options-for-twenty-twenty.php:166
actionwp_loadedextra-options-for-twenty-twenty.php:244
actioncustomize_registerextra-options-for-twenty-twenty.php:338
actioncustomize_preview_initextra-options-for-twenty-twenty.php:455
actioninitextra-options-for-twenty-twenty.php:486
actionenqueue_block_editor_assetsextra-options-for-twenty-twenty.php:498
actioncustomize_controls_enqueue_scriptsextra-options-for-twenty-twenty.php:516
filterbody_classextra-options-for-twenty-twenty.php:539
actionget_template_partextra-options-for-twenty-twenty.php:546
filterthe_titleextra-options-for-twenty-twenty.php:564
actionwp_headextra-options-for-twenty-twenty.php:577
actiontemplate_redirectextra-options-for-twenty-twenty.php:733
Maintenance & Trust

Extra Options For The Twenty Twenty Theme Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedDec 13, 2019
PHP min version5.5
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Extra Options For The Twenty Twenty Theme Developer Profile

acosmin

6 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Extra Options For The Twenty Twenty Theme

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/extra-options-for-twenty-twenty/css/extra-options-for-twenty-twenty.css/wp-content/plugins/extra-options-for-twenty-twenty/js/extra-options-for-twenty-twenty.js
Script Paths
/wp-content/plugins/extra-options-for-twenty-twenty/js/extra-options-for-twenty-twenty.js
Version Parameters
extra-options-for-twenty-twenty/css/extra-options-for-twenty-twenty.css?ver=extra-options-for-twenty-twenty/js/extra-options-for-twenty-twenty.js?ver=

HTML / DOM Fingerprints

CSS Classes
tteo2020-transparent-header-metatteo2020-transparent-header-input
HTML Comments
<!-- Transparent header<!-- Cover template logo --><!-- Footer credits --><!-- The theme has its own theme mods for footer -->+8 more
Data Attributes
data-tteo2020-transparent-header
JS Globals
tteo2020_transparent_header_opt
FAQ

Frequently Asked Questions about Extra Options For The Twenty Twenty Theme