
Illdy Companion Security & Risk Analysis
wordpress.org/plugins/illdy-companionIlldy Companion is a companion plugin for Illdy WordPress theme by Colorlib.com.
Is Illdy Companion Safe to Use in 2026?
Generally Safe
Score 92/100Illdy Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "illdy-companion" v2.1.4 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices by avoiding dangerous functions, utilizing prepared statements exclusively for SQL queries, and showing no recorded vulnerability history or critical taint flows. The absence of external HTTP requests and file operations further contributes to its security. However, a significant concern arises from the presence of one AJAX handler that lacks proper authentication checks. This creates a direct entry point for potential attackers, especially when combined with the complete absence of nonce checks. While the plugin boasts a high percentage of properly escaped output, the unprotected AJAX handler represents a clear weakness that could be exploited if it performs sensitive actions or processes user-supplied data without validation.
The static analysis reveals a small attack surface, with the primary risk stemming from the unprotected AJAX endpoint. The lack of nonce checks on this handler amplifies the risk, as it could be triggered by any user, authenticated or not. The taint analysis and vulnerability history are reassuring, indicating no known critical issues or past exploits. Nevertheless, the identified unprotected AJAX handler represents a tangible security gap that requires immediate attention to harden the plugin's defenses against unauthorized access and potential manipulation.
Key Concerns
- AJAX handler without authentication check
- Missing nonce checks on AJAX handlers
- Moderate output escaping (68% properly escaped)
Illdy Companion Security Vulnerabilities
Illdy Companion Release Timeline
Illdy Companion Code Analysis
Output Escaping
Data Flow Analysis
Illdy Companion Attack Surface
AJAX Handlers 1
WordPress Hooks 26
Maintenance & Trust
Illdy Companion Maintenance & Trust
Maintenance Signals
Community Trust
Illdy Companion Alternatives
Shapely Companion
shapely-companion
Shapely Companion is a companion plugin for Shapely WordPress theme by Colorlib.com.
Theme Demo Importer and Patterns Library for CozyThemes – Cozy Essential Addons
cozy-essential-addons
Cozy Essential Addons is the free WordPress plugin for Custom post type and provides basic skeletal for custom post type list.
Conversions Extensions
conversions-extensions
Adds homepage sections, one click demo imports, social icons, and other features to Conversions theme for WordPress.
BuddyPress Portfolio
buddypress-portfolio
This Buddypress plugin allows each user to create his portfolio on your website.
WP Live Portfolio
wp-live-portfolio
Showcase your website design work and website demos from the live URL. Plugin shows desktop, tab and mobile view of the live link.
Illdy Companion Developer Profile
11 plugins · 420K total installs
How We Detect Illdy Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/illdy-companion/assets/css/admin.css/wp-content/plugins/illdy-companion/assets/css/font-awesome.min.css/wp-content/plugins/illdy-companion/assets/css/jquery.fonticonpicker.css/wp-content/plugins/illdy-companion/assets/css/jquery.fonticonpicker.grey.min.css/wp-content/plugins/illdy-companion/assets/js/iconpicker.min.js/wp-content/plugins/illdy-companion/assets/js/admin.js/wp-content/plugins/illdy-companion/assets/js/widget-text-editor.js/wp-content/plugins/illdy-companion/assets/js/iconpicker.min.js/wp-content/plugins/illdy-companion/assets/js/admin.js/wp-content/plugins/illdy-companion/assets/js/widget-text-editor.jsilldy-companion/assets/css/admin.css?ver=illdy-companion/assets/css/font-awesome.min.css?ver=illdy-companion/assets/css/jquery.fonticonpicker.css?ver=illdy-companion/assets/css/jquery.fonticonpicker.grey.min.css?ver=illdy-companion/assets/js/iconpicker.min.js?ver=illdy-companion/assets/js/admin.js?ver=illdy-companion/assets/js/widget-text-editor.js?ver=HTML / DOM Fingerprints
illdy-companion-admin-cssilldy-companion-iconpicker-cssilldy-companion-iconpicker-theme-cssilldy-widget-recent-postsilldy-widget-skillilldy-widget-projectilldy-widget-serviceilldy-widget-counter+4 moredata-sectioniddata-elementidilldyCompanion