
Kenta Companion Security & Risk Analysis
wordpress.org/plugins/kenta-companionKenta Companion is an extension to the Kenta theme. It provides a lot of features and one-click demo import for Kenta Theme.
Is Kenta Companion Safe to Use in 2026?
Mostly Safe
Score 78/100Kenta Companion is generally safe to use. 1 past CVE were resolved. Keep it updated.
The kenta-companion plugin v1.3.3 exhibits a mixed security posture. On the positive side, its static analysis reveals a commendably small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication checks. Furthermore, all identified SQL queries are properly prepared, and a good number of capability checks and nonce checks are in place. However, the presence of the `unserialize` function is a significant concern, as it can be a vector for remote code execution if used with untrusted input. While taint analysis shows no flows with unsanitized paths, this doesn't mitigate the inherent risk of `unserialize` itself.
The vulnerability history presents a clear pattern of past security issues, specifically a medium-severity Cross-Site Request Forgery (CSRF) vulnerability that was last patched (or discovered) in 2026. The fact that one CVE is currently unpatched is a critical warning sign, even if it's categorized as medium severity. This suggests a potential for past vulnerabilities to resurface or that the plugin maintainers may not be consistently addressing security flaws promptly. The overall conclusion is that while the plugin has strengths in limiting its direct attack surface, the presence of a dangerous function like `unserialize` and an unpatched historical vulnerability necessitate careful consideration and vigilance.
Key Concerns
- Unpatched CVE found
- Dangerous function: unserialize used
- Bundled library (Freemius v1.0) may be outdated
Kenta Companion Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Kenta Companion <= 1.3.3 - Cross-Site Request Forgery
Kenta Companion Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Kenta Companion Attack Surface
WordPress Hooks 31
Maintenance & Trust
Kenta Companion Maintenance & Trust
Maintenance Signals
Community Trust
Kenta Companion Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Kenta Companion Developer Profile
25 plugins · 14K total installs
How We Detect Kenta Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kenta-companion/assets/css/kenta-admin.css/wp-content/plugins/kenta-companion/assets/css/kenta-admin.min.css/wp-content/plugins/kenta-companion/assets/js/kenta-admin.js/wp-content/plugins/kenta-companion/assets/js/kenta-admin.min.js/wp-content/plugins/kenta-companion/vendor/autoload.phpkenta-companion/style.css?ver=kenta-companion/script.js?ver=HTML / DOM Fingerprints
kenta-companion-admin-wrapdata-kenta-companionKentaCompanion/wp-json/kenta-companion/v1/demos