
Maja Envato Security & Risk Analysis
wordpress.org/plugins/maja-envatoThe Maja Envato plug-in is a widget as well as a shortcode to display thumbnails from the Envato Marketplaces like Themeforest.
Is Maja Envato Safe to Use in 2026?
Generally Safe
Score 85/100Maja Envato has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "maja-envato" v1.0 plugin presents a mixed security posture. On the positive side, the plugin demonstrates a strong adherence to secure database practices, with all SQL queries utilizing prepared statements. It also has a very limited attack surface with only one shortcode and no apparent AJAX handlers or REST API routes exposed without proper checks. Furthermore, the plugin has no recorded vulnerability history (CVEs), suggesting a history of relatively secure development or a lack of prior scrutiny.
However, significant security concerns are raised by the static analysis. The presence of the `create_function` call is a critical red flag, as this function is notoriously insecure and can be exploited for remote code execution if not handled with extreme care and sanitization. Additionally, the fact that 0% of the 35 output operations are properly escaped is a severe weakness. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the WordPress admin area or even the front end, depending on where the output is rendered. The absence of nonce checks and capability checks on the identified entry point (the shortcode) is also concerning, as it means that arbitrary users could potentially trigger the shortcode's functionality without proper authorization or verification, opening the door for unintended actions.
In conclusion, while the plugin shows promise in its database interactions and has a clean vulnerability history, the identified code signals (especially `create_function` and unescaped output) and lack of crucial security checks point to significant, exploitable weaknesses. These issues outweigh the positive aspects and necessitate immediate attention to mitigate potential risks.
Key Concerns
- Unescaped output (XSS risk)
- Dangerous function used (create_function)
- Missing nonce checks
- Missing capability checks
Maja Envato Security Vulnerabilities
Maja Envato Release Timeline
Maja Envato Code Analysis
Dangerous Functions Found
Output Escaping
Maja Envato Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Maja Envato Maintenance & Trust
Maintenance Signals
Community Trust
Maja Envato Alternatives
GS Portfolio for Envato
gs-envato-portfolio
Best Responsive Envato Portfolio Plugin to display Themeforest & Codecanyon Items.
My Envato
my-envato
A super simple plugin to display your recent 25 items from an Envato Marketplace.
Meks ThemeForest Smart Widget
meks-themeforest-smart-widget
Easily display ThemeForest items inside WordPress widget.
Envato Marketplace Widget
envato-marketplace-widget
Widget to display recent or popular items from the Envato marketplace.
EM Purchase Code Validator
em-purchase-code-validator
This is a simple plugin to validate your customer purchase code from Envato Market.
Maja Envato Developer Profile
2 plugins · 20 total installs
How We Detect Maja Envato
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/maja-envato/css/maja-envato.css/wp-content/plugins/maja-envato/js/maja-envato.js/wp-content/plugins/maja-envato/js/maja-envato.jsmaja-envato/css/maja-envato.css?ver=maja-envato/js/maja-envato.js?ver=HTML / DOM Fingerprints
maja-envato-thumbsdata-envato-iddata-envato-type[majaenvato]