
FacetWP Manipulator Security & Risk Analysis
wordpress.org/plugins/facetwp-manipulatorFacetWP Manipulator allows you to add code to specific FacetWP filters and Actions to manipulate functionality without hard coding it to the theme.
Is FacetWP Manipulator Safe to Use in 2026?
Generally Safe
Score 85/100FacetWP Manipulator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "facetwp-manipulator" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the analysis indicates a lack of dangerous functions, file operations, and external HTTP requests, which are common vectors for exploitation. The use of prepared statements for all SQL queries and a high percentage of properly escaped output are excellent security practices.
However, there are a few areas for potential improvement. The complete absence of capability checks, while coupled with a minimal attack surface, could be a concern if the plugin's functionality were to expand in the future. While two nonce checks are present, their context and coverage are not detailed here. The taint analysis showing zero flows, while positive, is based on a very limited analysis (zero flows analyzed). The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator of its development and maintenance. Overall, this plugin appears secure for its current scope, but vigilance regarding future updates and the addition of any new entry points is recommended.
Key Concerns
- No capability checks implemented
- Taint analysis limited (0 flows analyzed)
FacetWP Manipulator Security Vulnerabilities
FacetWP Manipulator Code Analysis
Output Escaping
FacetWP Manipulator Attack Surface
WordPress Hooks 16
Maintenance & Trust
FacetWP Manipulator Maintenance & Trust
Maintenance Signals
Community Trust
FacetWP Manipulator Alternatives
FacetWP Manipulator Developer Profile
6 plugins · 1K total installs
How We Detect FacetWP Manipulator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/facetwp-manipulator/assets/js/jquery.baldrick.js/wp-content/plugins/facetwp-manipulator/assets/js/handlebars-latest.js/wp-content/plugins/facetwp-manipulator/assets/controls/handlebars/handlebars-control.js/wp-content/plugins/facetwp-manipulator/assets/js/handlebars.baldrick.js/wp-content/plugins/facetwp-manipulator/fwpmanip-bootstrap.php/wp-content/plugins/facetwp-manipulator/classes/fwpmanip.php/wp-content/plugins/facetwp-manipulator/classes/fwpmanip/ui/control/handlebars.php/wp-content/plugins/facetwp-manipulator/classes/fwpmanip/ui/control/item.phpfacetwp-manipulator/style.css?ver=facetwp-manipulator/script.js?ver=HTML / DOM Fingerprints
fwpmanip-tab-canvasfwpmanip-item-editfwpmanip-item-removedata-appdata-templatedata-datadata-contentdata-statedata-defaultfwpmanip_item_control_modalfwpmanip_item_control_modal_handler