License For Envato Security & Risk Analysis

wordpress.org/plugins/license-envato

"License For Envato" is a Envato theme & plugin license management Software.

8K active installs v1.1.0 PHP 7.2+ WP 6.0+ Updated Dec 17, 2025
envato-licenselicenselicense-envatolicense-managerplugin-license
94
A · Safe
CVEs total2
Unpatched0
Last CVEApr 21, 2025
Safety Verdict

Is License For Envato Safe to Use in 2026?

Generally Safe

Score 94/100

License For Envato has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Apr 21, 2025Updated 3mo ago
Risk Assessment

The 'license-envato' plugin v1.1.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a commendably low attack surface with no unprotected entry points, all SQL queries utilizing prepared statements, and a high percentage of properly escaped output. The presence of numerous nonce and capability checks further suggests a commitment to secure development practices. However, the plugin's vulnerability history is a significant concern, with two known CVEs, including a past critical vulnerability related to PHP Remote File Inclusion and Cross-Site Scripting. While there are currently no unpatched vulnerabilities, this history indicates a recurring pattern of severe security flaws, suggesting potential underlying architectural weaknesses or a lack of rigorous security testing in past development cycles. The external HTTP requests, though few, could be a potential vector for supply chain attacks if not handled with utmost care and validation. The absence of any critical or high severity taint flows in the current analysis is a positive sign for this version, but the historical context necessitates ongoing vigilance.

Key Concerns

  • Past critical vulnerability history
  • Past medium vulnerability history
  • Presence of external HTTP requests
Vulnerabilities
2

License For Envato Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
1

2 total CVEs

CVE-2025-39399critical · 9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

License For Envato <= 1.0.0 - Unauthenticated Local File Inclusion

Apr 21, 2025 Patched in 1.1.0 (24d)
CVE-2025-32566medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

License For Envato <= 1.0.0 - Reflected Cross-Site Scripting

Apr 10, 2025 Patched in 1.1.0 (35d)
Code Analysis
Analyzed Mar 16, 2026

License For Envato Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
1
63 escaped
Nonce Checks
8
Capability Checks
5
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

98% escaped64 total outputs
Data Flows
All sanitized

Data Flow Analysis

8 flows
prepare_items (includes\Admin\Allusers.php:108)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

License For Envato Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuincludes\Admin\Menu.php:22
actionadmin_initincludes\Admin\Menu.php:43
actionrest_api_initincludes\API.php:18
actionwp_enqueue_scriptsincludes\Assets.php:18
actionadmin_enqueue_scriptsincludes\Assets.php:19
actionplugins_loadedlicense-envato.php:108
actionplugins_loadedlicense-envato.php:130
actionplugins_loadedlicense-envato.php:131
Maintenance & Trust

License For Envato Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 17, 2025
PHP min version7.2
Downloads60K

Community Trust

Rating0/100
Number of ratings0
Active installs8K
Developer Profile

License For Envato Developer Profile

Ashraful Sarkar Naiem

4 plugins · 9K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect License For Envato

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/license-envato/assets/css/style.css/wp-content/plugins/license-envato/assets/js/main.js
Script Paths
/wp-content/plugins/license-envato/assets/js/main.js
Version Parameters
license-envato/assets/css/style.css?ver=license-envato/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
license-envato-notice-successlicense-envato-notice-errorlicense-envato-settings-wraplicense-envato-table-wrap
HTML Comments
Copyright (c) 2023 Ashraful Sarkar NaiemThis program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be usefulThis is an add-on for WordPress
Data Attributes
data-plugin-id="license-envato"
JS Globals
license_envato_ajax_object
FAQ

Frequently Asked Questions about License For Envato