
Gutenverse Companion Security & Risk Analysis
wordpress.org/plugins/gutenverse-companionCompanion plugin for Gutenverse base themes
Is Gutenverse Companion Safe to Use in 2026?
Generally Safe
Score 100/100Gutenverse Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "gutenverse-companion" v2.1.8 exhibits a mixed security posture. On the positive side, the code demonstrates strong practices in its SQL querying, exclusively using prepared statements, and all identified output operations are properly escaped. Furthermore, the plugin has no recorded vulnerability history, suggesting a generally stable codebase.
However, significant concerns arise from the attack surface. All three identified entry points – two AJAX handlers and one REST API route – lack proper authentication or permission checks. This presents a considerable risk, as any unauthenticated user could potentially interact with these endpoints and trigger unintended or malicious actions. The presence of one flow with an unsanitized path in the taint analysis, while not classified as critical or high, still warrants attention as it indicates a potential avenue for path traversal or similar vulnerabilities.
In conclusion, while the plugin benefits from secure data handling practices and a clean vulnerability history, the lack of access control on its entry points is a critical weakness. The presence of an unsanitized path also adds to the risk. These issues, if exploited, could lead to unauthorized access or data manipulation, overriding the strengths in other security aspects.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Flows with unsanitized paths
- No nonce checks on AJAX handlers
Gutenverse Companion Security Vulnerabilities
Gutenverse Companion Code Analysis
Output Escaping
Data Flow Analysis
Gutenverse Companion Attack Surface
AJAX Handlers 2
REST API Routes 1
WordPress Hooks 48
Maintenance & Trust
Gutenverse Companion Maintenance & Trust
Maintenance Signals
Community Trust
Gutenverse Companion Alternatives
FSE Themes Builder
gutenverse-themes-builder
Begin creating your theme effortlessly, with no coding required.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
essential-blocks
Gutenberg block editor with AI. 70+ Gutenberg blocks, patterns, WooCommerce blocks, post grid, gallery, menu with Gutenberg block library.
Genesis Custom Blocks
genesis-custom-blocks
Custom blocks for WordPress made easy.
Better Block Editor (BBE)
better-block-editor
Better Block Editor (BBE) — responsive layout controls, on-scroll animations, and pre-made site templates for Block Editor.
Gutenverse Companion Developer Profile
6 plugins · 57K total installs
How We Detect Gutenverse Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gutenverse-companion/assets/css/companion.css/wp-content/plugins/gutenverse-companion/assets/js/companion.js/wp-content/plugins/gutenverse-companion/lib/dependencies/companion.asset.phpgutenverse-companion/assets/css/companion.css?ver=gutenverse-companion/assets/js/companion.js?ver=HTML / DOM Fingerprints
gutenverse-companion-dashboarddata-gutenverse-componentdata-gutenverse-typeGutenverseRootConfigGutenverseCompanionConfig/wp-json/gutenverse-server/v1/wp-json/gutenverse-banner/v1/unibizdata