Fundamento Security & Risk Analysis

wordpress.org/plugins/fundamento

Fundamento creates the ability to easily add custom skins and padding-presets into your Elementor-based Wordpress website.

70 active installs v1.1.10 PHP 7.4+ WP 5.2+ Updated Oct 28, 2024
elementorglobalsskintemplate
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Fundamento Safe to Use in 2026?

Generally Safe

Score 92/100

Fundamento has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'fundamento' plugin v1.1.10 exhibits a strong security posture. The code analysis reveals a complete absence of detectable attack surface points, including AJAX handlers, REST API routes, shortcodes, and cron events. Furthermore, the code demonstrates excellent security practices by having zero dangerous functions, zero file operations, zero external HTTP requests, and a complete adherence to prepared statements for all SQL queries. The absence of unsanitized taint flows and proper output escaping further bolster its security, indicating that developers have taken significant care to prevent common vulnerabilities.

The plugin's vulnerability history is also pristine, with zero recorded CVEs across all severity levels and no recent vulnerabilities. This pattern strongly suggests a commitment to secure coding and thorough testing. The plugin appears to be exceptionally well-hardened against common web application attacks. However, the complete lack of nonce and capability checks, while not necessarily a direct vulnerability in isolation given the zero attack surface, represents a missed opportunity to further secure any potential future entry points should they be introduced. This is a minor point in the current state, but worth noting for ongoing development.

In conclusion, 'fundamento' v1.1.10 is a remarkably secure plugin. Its strengths lie in its minimal attack surface, diligent use of secure coding practices for database interactions and output handling, and a spotless vulnerability record. The only minor area for improvement, which doesn't detract from its current excellent security, would be the implementation of capability checks even for internal logic, as a defensive programming measure.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Fundamento Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fundamento Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Fundamento Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionplugins_loadedfundamento.php:27
actionelementor/element/before_section_startincludes\controls\padding-control.php:28
actionelementor/preview/enqueue_stylesincludes\controls\skin-control.php:51
actionelementor/element/after_section_startincludes\controls\skin-control.php:67
actionelementor/widget/render_contentincludes\controls\skin-control.php:108
actionelementor/frontend/before_renderincludes\controls\skin-control.php:157
actionelementor/initincludes\plugin.php:85
actionadmin_noticesincludes\plugin.php:102
actionadmin_noticesincludes\plugin.php:108
actionadmin_noticesincludes\plugin.php:114
actionadmin_noticesincludes\plugin.php:259
actionadmin_noticesincludes\plugin.php:279
actionelementor/frontend/before_renderincludes\plugin.php:314
Maintenance & Trust

Fundamento Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedOct 28, 2024
PHP min version7.4
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs70
Developer Profile

Fundamento Developer Profile

w3dev

3 plugins · 1K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fundamento

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fundamento/assets/css/skins.css/wp-content/plugins/fundamento/assets/js/skins.js
Script Paths
/wp-content/plugins/fundamento/assets/js/skins.js
Version Parameters
fundamento/assets/css/skins.css?ver=fundamento/assets/js/skins.js?ver=

HTML / DOM Fingerprints

CSS Classes
skin-
Data Attributes
data-skin-options
JS Globals
Fundamento
FAQ

Frequently Asked Questions about Fundamento