
Hunk Companion Security & Risk Analysis
wordpress.org/plugins/hunk-companionAdds customizer settings and controls to the Gogo Theme.
Is Hunk Companion Safe to Use in 2026?
Generally Safe
Score 93/100Hunk Companion has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The hunk-companion v2.0.1 plugin exhibits a mixed security posture. While it demonstrates some good practices like a high percentage of prepared SQL statements and a decent amount of output escaping, significant concerns arise from its attack surface and historical vulnerabilities. A notable risk is the presence of 6 unprotected AJAX handlers, representing a considerable entry point for potential unauthorized actions. The plugin also has a history of critical vulnerabilities, specifically related to missing authorization, which is a serious red flag. Although there are currently no unpatched critical vulnerabilities, the past occurrence of two critical CVEs, both due to missing authorization, suggests a recurring weakness that requires careful monitoring and prompt patching of any future disclosures. The taint analysis did not reveal critical or high severity issues, which is a positive sign, but the unsanitized paths found warrant attention, especially in conjunction with the unprotected AJAX endpoints.
Key Concerns
- Unprotected AJAX handlers present
- History of critical CVEs (Missing Authorization)
- Flows with unsanitized paths found
Hunk Companion Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Hunk Companion <= 1.8.5 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation
Hunk Companion Release Timeline
Hunk Companion Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Hunk Companion Attack Surface
AJAX Handlers 26
Shortcodes 7
WordPress Hooks 136
Maintenance & Trust
Hunk Companion Maintenance & Trust
Maintenance Signals
Community Trust
Hunk Companion Alternatives
ThemeHunk Customizer
themehunk-customizer
ThemeHunk Customiser plugin will add features of testimonial, team and service.
Theme Demo Importer and Patterns Library for CozyThemes – Cozy Essential Addons
cozy-essential-addons
Cozy Essential Addons is the free WordPress plugin for Custom post type and provides basic skeletal for custom post type list.
Organic Builder Widgets – Simple WordPress Page Builder
organic-customizer-widgets
A simple WordPress page builder, Organic Builder Widgets provides a collection of 12 custom widgets to be used in the Customizer as content sections.
ThemeFarmer Companion
themefarmer-companion
Advance Extension For ThemeFarmer Theme. enjoy full functionality of ThemeFarmer theme by installing this plugin.
Walker Core
walker-core
Walker Core is the companion plugin for WalkerWP Themes, which provides core functionality and custom post type for the themes.
Hunk Companion Developer Profile
49 plugins · 64K total installs
How We Detect Hunk Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hunk-companion/gogolite/css/gogo-css/section.css/wp-content/plugins/hunk-companion/gogolite/css/gogo-css/animate.css/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/owl.carousel.js/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/typer.js/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/isotope.pkgd.js/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/vertical-navigation-modernizr.js/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/vertical-navigation-main.js/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/wow.min.js+13 more/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/owl.carousel.js/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/typer.js/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/isotope.pkgd.js/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/vertical-navigation-modernizr.js/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/vertical-navigation-main.js/wp-content/plugins/hunk-companion/gogolite/js/gogo-js/wow.min.js+9 morehunk-companion/gogolite/css/gogo-css/section.css?ver=hunk-companion/gogolite/css/gogo-css/animate.css?ver=hunk-companion/gogolite/js/gogo-js/owl.carousel.js?ver=hunk-companion/gogolite/js/gogo-js/typer.js?ver=hunk-companion/gogolite/js/gogo-js/isotope.pkgd.js?ver=hunk-companion/gogolite/js/gogo-js/vertical-navigation-modernizr.js?ver=hunk-companion/gogolite/js/gogo-js/vertical-navigation-main.js?ver=hunk-companion/gogolite/js/gogo-js/wow.min.js?ver=hunk-companion/gogolite/js/gogo-js/custom.js?ver=hunk-companion/almaira-shop/assets/css/owl.carousel.css?ver=hunk-companion/almaira-shop/assets/css/swiper.css?ver=hunk-companion/almaira-shop/assets/js/swiper.js?ver=hunk-companion/almaira-shop/assets/js/almaira-custom.js?ver=hunk-companion/open-shop/assets/js/jssor.slider.min.js?ver=hunk-companion/open-shop/assets/js/custom.js?ver=hunk-companion/open-shop/open-shop-admin/woo/js/woocommerce.js?ver=hunk-companion/portfoliolite/admin/css/customizer.css?ver=hunk-companion/portfoliolite/admin/js/customizer.js?ver=hunk-companion/th-shop-mania/assets/css/th-sm-customizer.css?ver=hunk-companion/th-shop-mania/assets/js/th-sm-customizer.js?ver=hunk-companion/th-shop-mania/assets/js/th-sm-admin.js?ver=HTML / DOM Fingerprints
gogolitefrontendajaxopen_shop