
Fable Extra Security & Risk Analysis
wordpress.org/plugins/fable-extraUsed for WP Fable Themes.
Is Fable Extra Safe to Use in 2026?
Generally Safe
Score 92/100Fable Extra has a strong security track record. Known vulnerabilities have been patched promptly.
The "fable-extra" plugin v1.0.11 presents a mixed security posture. While it demonstrates good practices such as a high percentage of properly escaped output and a lack of external HTTP requests, significant concerns arise from its attack surface and past vulnerability history. The presence of 12 unprotected AJAX handlers is a major weakness, providing numerous potential entry points for attackers without proper authentication. Furthermore, the use of the `unserialize` function, while not directly flagged by taint analysis in this version, is a known dangerous function that historically has led to vulnerabilities if not handled with extreme care, especially when processing untrusted input.
The plugin's vulnerability history is particularly alarming. With 3 known CVEs, including a critical and a high severity vulnerability, it indicates a pattern of insecure coding practices. The types of past vulnerabilities (RFI, SQL Injection, XSS) are common and severe, suggesting recurring weaknesses in input validation and sanitization. The fact that the last vulnerability was very recent (April 2025) and that none are currently unpatched is a positive sign, but the historical prevalence of critical issues cannot be ignored. Overall, the plugin has some strengths in modern development practices, but the large number of unprotected entry points and its history of serious vulnerabilities make it a notable security risk.
Key Concerns
- High number of unprotected AJAX handlers
- Use of dangerous function (unserialize)
- History of critical severity CVEs
- History of high severity CVEs
- History of medium severity CVEs
- SQL queries with low prepared statement usage
Fable Extra Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Fable Extra <= 1.0.6 - Unauthenticated Local File Inclusion
Fable Extra <= 1.0.6 - Unauthenticated SQL Injection
Fable Extra <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Fable Extra Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Fable Extra Attack Surface
AJAX Handlers 20
Shortcodes 2
WordPress Hooks 45
Maintenance & Trust
Fable Extra Maintenance & Trust
Maintenance Signals
Community Trust
Fable Extra Alternatives
Rara One Click Demo Import
rara-one-click-demo-import
Make your website look like the live demo of the theme with a click!
SKT Themes Demo Import
skt-themes-demo-importer
Live demo content can be imported quickly in just one click including all widgets and settings.
Theme Demo Import
theme-demo-import
Quickly import demo content, widgets and settings in one click. Made for theme authors to simplify importing demo content for their users.
Starter Templates by Gradient Themes
gradient-starter-templates
Setup you site with dummy data easily. Import settings, widgets and content with one click. Your dummy data must have ZIP file of xml, dat and wie fi …
Flawless Themes Demo Importer
flawless-themes-demo-importer
Flawless Themes Demo Importer plugin helps you import demo content for various free themes of flawlessthemes . Flawless Themes are dedicated to creati …
Fable Extra Developer Profile
8 plugins · 8K total installs
How We Detect Fable Extra
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fable-extra/inc/woo-features/assets/css/fable-extra-woocompare.css/wp-content/plugins/fable-extra/inc/woo-features/assets/js/fable-extra-woocompare.js/wp-content/plugins/fable-extra/inc/woo-features/assets/js/fable-extra-woocompare.min.js/wp-content/plugins/fable-extra/inc/woo-features/assets/css/tablesaw.css/wp-content/plugins/fable-extra/inc/woo-features/assets/js/tablesaw.js/wp-content/plugins/fable-extra/inc/woo-features/assets/js/tablesaw.min.js/wp-content/plugins/fable-extra/inc/woo-features/assets/js/tablesaw-init.js/wp-content/plugins/fable-extra/inc/woo-features/assets/js/tablesaw-init.min.js/wp-content/plugins/fable-extra/inc/woo-features/assets/js/fable-extra-woocompare.js/wp-content/plugins/fable-extra/inc/woo-features/assets/js/fable-extra-woocompare.min.js/wp-content/plugins/fable-extra/inc/woo-features/assets/js/tablesaw.js/wp-content/plugins/fable-extra/inc/woo-features/assets/js/tablesaw.min.js/wp-content/plugins/fable-extra/inc/woo-features/assets/js/tablesaw-init.js/wp-content/plugins/fable-extra/inc/woo-features/assets/js/tablesaw-init.min.jsfable-extra/style.css?ver=fable-extra-woocompare.css?ver=fable-extra-woocompare.js?ver=tablesaw.css?ver=tablesaw.js?ver=tablesaw-init.js?ver=HTML / DOM Fingerprints
fableExtraWoocompare