
ISTK Add-On Security & Risk Analysis
wordpress.org/plugins/istk-add-onThis plugin adds features for theme "ISTK Portfolio".
Is ISTK Add-On Safe to Use in 2026?
Generally Safe
Score 100/100ISTK Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'istk-add-on' v1.2 plugin exhibits a generally strong security posture, primarily due to the absence of known vulnerabilities and critical findings in the static and taint analysis. The code effectively utilizes prepared statements for all SQL queries and includes nonce and capability checks, which are good practices for securing WordPress plugins. There are no indications of dangerous functions, file operations, or external HTTP requests, further contributing to its secure design.
However, a significant concern lies in the output escaping, with only 17% of 36 outputs being properly escaped. This leaves a considerable portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks, especially if the content being displayed originates from user input or untrusted sources. While the attack surface is relatively small and appears to be protected by authentication checks, the lack of comprehensive output escaping represents a tangible risk that should be addressed.
The plugin's clean vulnerability history is a positive indicator, suggesting a consistent effort towards security or a lack of discoverable vulnerabilities thus far. Combined with the strong use of prepared statements and access control checks, the plugin demonstrates a good foundation. The primary weakness is the insufficient output escaping, which, despite the absence of historical high-severity vulnerabilities, poses a realistic threat that could be exploited.
Key Concerns
- Insufficient output escaping (17% of 36 outputs)
ISTK Add-On Security Vulnerabilities
ISTK Add-On Release Timeline
ISTK Add-On Code Analysis
Output Escaping
ISTK Add-On Attack Surface
Shortcodes 4
WordPress Hooks 16
Maintenance & Trust
ISTK Add-On Maintenance & Trust
Maintenance Signals
Community Trust
ISTK Add-On Alternatives
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Visual Portfolio, Photo Gallery & Post Grid
visual-portfolio
Powerful WordPress gallery plugin for stunning photo, video & album galleries with advanced layouts and flexible block editing.
Portfolio Post Type
portfolio-post-type
This plugin registers a custom post type for portfolio items. It also registers separate portfolio taxonomies for tags and categories.
Premium Portfolio Features for Phlox theme
auxin-portfolio
Showcase your projects beautifully in Phlox theme
Themify Portfolio Post
themify-portfolio-post
Add a simple Portfolio post type to your site.
ISTK Add-On Developer Profile
2 plugins · 180 total installs
How We Detect ISTK Add-On
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/istk-add-on/assets/style.css/wp-content/plugins/istk-add-on/assets/admin.css/wp-content/plugins/istk-add-on/assets/upload_category_image.js/wp-content/plugins/istk-add-on/assets/upload_category_image.jsistk-add-on/style.css?ver=istk-add-on/admin.css?ver=upload_category_image.js?ver=HTML / DOM Fingerprints
istk_add_on_category_imagework-data-areawork-data-tablework_data_noticeid="istk_add_on_category_image_thumb"id="istk_add_on_category_image_id"id="istk_add_on_category_image_upload"id="istk_add_on_category_image_delete"istk_add_on_transrate[istk_portfolio_category][istk_portfolio_tags][istk_cta_contact][istk_cta_download]