Long Toolkit Security & Risk Analysis

wordpress.org/plugins/long-toolkit

Create Admin fields, metabox, widget, taxonomy, menu meta, customizer fields quickly and friendly.

20 active installs v2.5 PHP + WP 4.5+ Updated Unknown
frameworkimportimporterone-click
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Long Toolkit Safe to Use in 2026?

Generally Safe

Score 100/100

Long Toolkit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The long-toolkit v2.5 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, exclusively using prepared statements, which significantly mitigates SQL injection risks. Furthermore, the absence of recorded CVEs and the clean taint analysis results indicate a low likelihood of known or easily exploitable vulnerabilities within the current version. However, a significant concern arises from the attack surface. The plugin exposes five AJAX handlers, and alarmingly, all of them lack authentication checks. This creates a substantial entry point for potential attackers to interact with the plugin's functionality without proper authorization, which could lead to unintended actions or data manipulation. While the plugin doesn't appear to have a history of vulnerabilities, the current implementation of unprotected AJAX endpoints presents an immediate and actionable security risk that warrants attention.

Key Concerns

  • AJAX handlers without authentication checks
Vulnerabilities
None known

Long Toolkit Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Long Toolkit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
104
193 escaped
Nonce Checks
6
Capability Checks
3
File Operations
14
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared4 total queries

Output Escaping

65% escaped297 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
update (includes\class-long-toolkit-menu.php:149)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Long Toolkit Attack Surface

Entry Points5
Unprotected5

AJAX Handlers 5

authwp_ajax_long_toolkit_importeraddons\importer\importer.php:68
authwp_ajax_long_toolkit_import_demoaddons\importer\importer.php:69
authwp_ajax_long_toolkit_autocomplete_post_typeincludes\admin-fields\field_autocomplete.php:198
authwp_ajax_long_toolkit_autocomplete_taxonomyincludes\admin-fields\field_autocomplete.php:199
authwp_ajax_add-taglong-toolkit.php:77
WordPress Hooks 38
actionadmin_enqueue_scriptsaddons\importer\importer.php:70
filterwp_import_post_data_rawaddons\importer\importer.php:222
filterwp_import_post_data_processedaddons\importer\importer.php:223
filterwp_import_post_metaaddons\importer\importer.php:224
filterlong_toolkit_importer_customizer_enable_defaulong_toolkit_imageaddons\importer\importer.php:272
filterlong_toolkit_importer_customzer_defaulong_toolkit_image_urladdons\importer\importer.php:273
actionadmin_initaddons\importer\importer.php:440
filterimport_post_meta_keyaddons\importer\wordpress-importer\wordpress-importer.php:102
filterhttp_request_timeoutaddons\importer\wordpress-importer\wordpress-importer.php:103
filterlong_toolkit_source_fontawesomeincludes\admin-fields\field_icon_picker.php:859
filterwp_edit_nav_menu_walkerincludes\class-long-toolkit-menu.php:42
actionwp_nav_menu_item_custom_fieldsincludes\class-long-toolkit-menu.php:43
actionwp_update_nav_menu_itemincludes\class-long-toolkit-menu.php:44
actionadd_meta_boxesincludes\class-long-toolkit-metabox.php:64
actionsave_postincludes\class-long-toolkit-metabox.php:65
actionsave_postincludes\class-long-toolkit-widget.php:79
actiondeleted_postincludes\class-long-toolkit-widget.php:80
actionswitch_themeincludes\class-long-toolkit-widget.php:81
actionadmin_enqueue_scriptsincludes\class-long-toolkit-widget.php:82
actionplugins_loadedlong-toolkit.php:68
actioncustomize_registerlong-toolkit.php:69
actioncustomize_controls_enqueue_scriptslong-toolkit.php:70
actionadmin_enqueue_scriptslong-toolkit.php:73
actionadmin_initlong-toolkit.php:74
actioncurrent_screenlong-toolkit.php:76
actionload-post.phplong-toolkit.php:79
actionload-post-new.phplong-toolkit.php:80
actionload-nav-menus.phplong-toolkit.php:82
actionin_admin_headerlong-toolkit.php:345
actioncustomize_controls_print_footer_scriptslong-toolkit.php:346
actioncustomize_registersample\customizer.php:365
filterlong_toolkit_menu_fieldssample\menu.php:7
actionlong_toolkit_metabox_initsample\post-meta.php:584
actionlong_toolkit_metabox_initsample\post-meta.php:613
actionlong_toolkit_metabox_initsample\post-meta.php:642
filterlong_toolkit_gmap_keysample\sample.php:22
actionlong_toolkit_termbox_initsample\taxonomy.php:261
actionwidgets_initsample\widget.php:63
Maintenance & Trust

Long Toolkit Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Long Toolkit Developer Profile

longbsvnu

3 plugins · 240 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Long Toolkit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Long Toolkit