Kenzap Features Security & Risk Analysis

wordpress.org/plugins/kenzap-features

A beautiful and easy customizable set of Gutenberg blocks to create features section for the new editor. Easily adjust the following parameters:

10 active installs v1.2.1 PHP 5.6+ WP 5.1+ Updated Nov 10, 2020
aboutfeaturesinfoservices
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Kenzap Features Safe to Use in 2026?

Generally Safe

Score 85/100

Kenzap Features has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "kenzap-features" v1.2.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions, file operations, or external HTTP requests. The complete reliance on prepared statements for SQL queries and proper output escaping demonstrates good secure coding practices. The plugin also appears to be mindful of permissions, with one capability check identified. The lack of any recorded vulnerabilities in its history further bolsters this assessment, indicating a history of stable and secure development.

While the static analysis reveals no immediate or critical security risks, the data also points to some areas that, while not explicitly problematic, could be improved. The absence of any nonce checks, while not a direct vulnerability given the limited attack surface, means that if new entry points were introduced in the future, they might be susceptible to CSRF attacks if not properly secured. Similarly, the single capability check suggests that while some authorization is in place, a broader implementation might be beneficial for future extensibility. The taint analysis reporting zero flows, while ideal, could also be due to the limited scope or nature of the analyzed code, and doesn't necessarily guarantee the absence of all potential taint issues in more complex scenarios. The overall conclusion is that the plugin is currently very secure, but the minimal attack surface and absence of certain security mechanisms (like nonces) mean that careful development practices would be crucial for any future updates or additions to its functionality.

Key Concerns

  • No nonce checks implemented
  • Limited observable authorization checks
Vulnerabilities
None known

Kenzap Features Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Kenzap Features Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Kenzap Features Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_initplugin.php:50
actionadmin_noticesplugin.php:51
actioninitplugin.php:69
filterbody_classplugin.php:77
filteradmin_body_classplugin.php:78
actionenqueue_block_assetssrc\init.php:55
actionenqueue_block_editor_assetssrc\init.php:94
Maintenance & Trust

Kenzap Features Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedNov 10, 2020
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Kenzap Features Developer Profile

WP Asia

7 plugins · 260 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kenzap Features

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kenzap-features/dist/blocks.style.build.css/wp-content/plugins/kenzap-features/dist/assets/owl.carousel.min.js/wp-content/plugins/kenzap-features/dist/assets/owl.carousel.min.css/wp-content/plugins/kenzap-features/feature-list-2/script.js/wp-content/plugins/kenzap-features/dist/blocks.build.js/wp-content/plugins/kenzap-features/dist/blocks.editor.build.css
Script Paths
/wp-content/plugins/kenzap-features/dist/blocks.build.js/wp-content/plugins/kenzap-features/dist/blocks.editor.build.css/wp-content/plugins/kenzap-features/dist/assets/owl.carousel.min.js/wp-content/plugins/kenzap-features/feature-list-2/script.js

HTML / DOM Fingerprints

CSS Classes
kenzap
Data Attributes
kenzap_features_gutenberg_path
JS Globals
kenzap_features_gutenberg_path
FAQ

Frequently Asked Questions about Kenzap Features