ExtraSpace Security & Risk Analysis

wordpress.org/plugins/extraspace

Add a small, unobtrusive tab to your site that opens a lightweight, accessible slide-in panel for announcements, promos, CTAs, custom HTML, or shortco …

0 active installs v1.1.1 PHP 7.4+ WP 6.0+ Updated Dec 24, 2025
announcementscall-to-actionmarketingpromotionslideout
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ExtraSpace Safe to Use in 2026?

Generally Safe

Score 100/100

ExtraSpace has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of the "extraspace" plugin v1.1.1 reveals a generally strong security posture. The plugin demonstrates excellent adherence to secure coding practices, with no identified dangerous functions, no direct SQL queries (all are prepared), and a high percentage of properly escaped output. The presence of nonce and capability checks, coupled with zero external HTTP requests and file operations, further strengthens its security. Crucially, the absence of any identified vulnerabilities in its history, including CVEs, suggests a well-maintained and likely secure plugin. There are no reported critical or high-severity issues from taint analysis, indicating a lack of easily exploitable data flow vulnerabilities.

However, the complete absence of any attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual for a plugin that is likely intended to provide some functionality. While this might indicate a highly specialized or passive plugin, it could also suggest that its functionality is deeply embedded within other WordPress core processes or hooks that were not identified as explicit entry points in this analysis. The 0 taint flows analyzed is also a notable point, as it leaves a portion of the plugin's internal data handling unverified by this specific analysis method. Despite these minor observations, the plugin exhibits robust security controls and a clean historical record.

Vulnerabilities
None known

ExtraSpace Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ExtraSpace Release Timeline

v1.1.1Current
Code Analysis
Analyzed Apr 16, 2026

ExtraSpace Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
69 escaped
Nonce Checks
2
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

87% escaped79 total outputs
Attack Surface

ExtraSpace Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actioninitextraspace.php:45
actioninitextraspace.php:46
actionadd_meta_boxesextraspace.php:47
actionsave_postextraspace.php:48
actionadmin_initextraspace.php:51
actionwp_enqueue_scriptsextraspace.php:55
actionwp_body_openextraspace.php:56
actionwp_footerextraspace.php:57
actionpre_get_postsextraspace.php:63
actionadmin_enqueue_scriptsextraspace.php:65
actionadmin_menuextraspace.php:1123
Maintenance & Trust

ExtraSpace Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 24, 2025
PHP min version7.4
Downloads147

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ExtraSpace Developer Profile

michaelgrover

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ExtraSpace

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/extraspace/assets/extraspace-admin-pages.css/wp-content/plugins/extraspace/assets/admin.js/wp-content/plugins/extraspace/assets/extraspace-frontend.js/wp-content/plugins/extraspace/assets/extraspace-frontend.css
Script Paths
/wp-content/plugins/extraspace/assets/extraspace-frontend.js
Version Parameters
extraspace-admin-pagesextraspace-admin-listextraspace-adminextraspace-frontend

HTML / DOM Fingerprints

CSS Classes
n96-spotlight-paneln96-spotlight-tabn96-spotlight-tab-hovern96-spotlight-tab-wigglen96-spotlight-closen96-spotlight-contentn96-spotlight-content-html
Data Attributes
data-extraspace-sidedata-extraspace-widthdata-extraspace-tab-labeldata-extraspace-tab-bgdata-extraspace-hover-borderdata-extraspace-wiggle-tease+4 more
JS Globals
extraspace_vars
FAQ

Frequently Asked Questions about ExtraSpace