
Lemmony Companion Security & Risk Analysis
wordpress.org/plugins/lemmony-companionThe Lemmony Companion is a companion plugin for the Lemmony theme. Adds additional block editor blocks needed for the best theme experience.
Is Lemmony Companion Safe to Use in 2026?
Generally Safe
Score 85/100Lemmony Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of lemmony-companion v1.2 reveals a generally positive security posture with several good practices in place. Notably, the plugin has a zero attack surface for direct entry points like AJAX handlers, REST API routes, and shortcodes. All SQL queries are correctly using prepared statements, which mitigates a significant class of vulnerabilities. The plugin also demonstrates good output escaping practices, with 85% of outputs being properly sanitized.
However, there are areas for improvement and potential concerns. The absence of nonce checks on any entry points is a significant omission. While the attack surface is currently zero, if new entry points are introduced without proper nonce validation, it could lead to Cross-Site Request Forgery (CSRF) vulnerabilities. The presence of file operations without further context is also a minor concern, as it could potentially be exploited if user-controlled input influences file paths or operations.
The vulnerability history is a strong positive indicator, showing no known CVEs and no previous vulnerability patterns. This suggests a generally well-coded and maintained plugin. In conclusion, lemmony-companion v1.2 exhibits strong foundational security through its limited attack surface and correct SQL handling. The primary risk lies in the lack of nonce checks, which, while not exploitable with the current zero entry points, represents a critical missing security control that should be addressed proactively.
Key Concerns
- Missing Nonce Checks
- File operations present (context needed)
Lemmony Companion Security Vulnerabilities
Lemmony Companion Code Analysis
Output Escaping
Lemmony Companion Attack Surface
WordPress Hooks 4
Maintenance & Trust
Lemmony Companion Maintenance & Trust
Maintenance Signals
Community Trust
Lemmony Companion Alternatives
Font Awesome
font-awesome
The official way to use Font Awesome Free or Pro icons on your WordPress site, brought to you by the Font Awesome team.
The Icon Block
icon-block
Easily add SVG icons and graphics to the WordPress block editor.
Custom Favicon – Easily Add a Favicon in WordPress
custom-favicon
Easily add a custom favicon and Apple touch icon to your WordPress site, including support for dark mode, SVG icons, and admin dashboard branding.
SVG Block
svg-block
Display an SVG image as a block, which can be used for displaying images, icons, dividers, buttons
JVM Rich Text Icons
jvm-rich-text-icons
Insert icons anywhere in your content — inline in text, headings, buttons, or as a standalone block.
Lemmony Companion Developer Profile
2 plugins · 4K total installs
How We Detect Lemmony Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lemmony-companion/blocks/accordion/index.js/wp-content/plugins/lemmony-companion/blocks/accordion/style.css/wp-content/plugins/lemmony-companion/blocks/counter/index.js/wp-content/plugins/lemmony-companion/blocks/counter/style.css/wp-content/plugins/lemmony-companion/blocks/icon/index.js/wp-content/plugins/lemmony-companion/blocks/icon/style.css/wp-content/plugins/lemmony-companion/blocks/post-featured-image-caption/index.js/wp-content/plugins/lemmony-companion/blocks/post-featured-image-caption/style.css+2 more/wp-content/plugins/lemmony-companion/blocks/counter/index.js/wp-content/plugins/lemmony-companion/blocks/icon/index.js/wp-content/plugins/lemmony-companion/blocks/post-featured-image-caption/index.js/wp-content/plugins/lemmony-companion/blocks/typing-text/index.js/wp-content/plugins/lemmony-companion/blocks/accordion/index.js?ver=/wp-content/plugins/lemmony-companion/blocks/accordion/style.css?ver=/wp-content/plugins/lemmony-companion/blocks/counter/index.js?ver=/wp-content/plugins/lemmony-companion/blocks/counter/style.css?ver=/wp-content/plugins/lemmony-companion/blocks/icon/index.js?ver=/wp-content/plugins/lemmony-companion/blocks/icon/style.css?ver=/wp-content/plugins/lemmony-companion/blocks/post-featured-image-caption/index.js?ver=/wp-content/plugins/lemmony-companion/blocks/post-featured-image-caption/style.css?ver=/wp-content/plugins/lemmony-companion/blocks/typing-text/index.js?ver=/wp-content/plugins/lemmony-companion/blocks/typing-text/style.css?ver=HTML / DOM Fingerprints
wp-block-lemmony-companion-accordionwp-block-lemmony-companion-counterwp-block-lemmony-companion-iconwp-block-lemmony-companion-post-featured-image-captionwp-block-lemmony-companion-typing-textlemmony_companion_faqs