Marin Companion Security & Risk Analysis

wordpress.org/plugins/marin-companion

Marin Companion is a companion plugin for Marin theme.

500 active installs v0.0.7 PHP + WP 4.0+ Updated Aug 21, 2025
adminfeaturedfrontpagetheme-pagewidgets
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Marin Companion Safe to Use in 2026?

Generally Safe

Score 100/100

Marin Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "marin-companion" v0.0.7 plugin exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code analysis reveals excellent adherence to secure coding practices, with no dangerous functions, no raw SQL queries (all prepared statements), and near-perfect output escaping. The plugin also avoids file operations and external HTTP requests, further reducing risk. The lack of any recorded vulnerabilities, including historical CVEs, suggests a mature and secure development process or a plugin that has not yet attracted significant security scrutiny due to its obscurity or limited functionality. While the lack of capability checks and nonce checks on entry points is a theoretical concern, the complete absence of entry points mitigates this risk in practice for this version. The plugin's strengths lie in its extremely small attack surface and robust internal coding practices. The primary weakness, if any, is the complete lack of explicit capability and nonce checks, which would be a significant concern if any entry points were present.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Marin Companion Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Marin Companion Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
269 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped271 total outputs
Attack Surface

Marin Companion Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioncustomize_registerinc\marin\customizer\frontpage-customizer-options.php:722
actioncustomize_registerinc\marin\customizer\frontpage-customizer-options.php:1411
filterpt-ocdi/import_filesinc\marin\demo-content\setup.php:55
actionpt-ocdi/after_importinc\marin\demo-content\setup.php:75
actionadmin_enqueue_scriptsinc\marin\demo-content\setup.php:93
filterocdi/plugin_page_setupinc\marin\demo-content\setup.php:108
filterocdi/register_pluginsinc\marin\demo-content\setup.php:145
actionmarin_above_footerinc\marin\front-page\section-footer-info.php:52
actionmarin_frontpageinc\marin\marin.php:50
actioninitmarin-companion.php:51
Maintenance & Trust

Marin Companion Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 21, 2025
PHP min version
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

Marin Companion Developer Profile

FARAZFRANK

28 plugins · 47K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
578 days
View full developer profile
Detection Fingerprints

How We Detect Marin Companion

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/marin-companion/inc/marin/marin.css/wp-content/plugins/marin-companion/inc/marin/marin.js
Script Paths
/wp-content/plugins/marin-companion/inc/marin/marin.js

HTML / DOM Fingerprints

CSS Classes
marin-companion-wrappermarin-companion-about-areamarin-companion-map-area
Data Attributes
data-marin-companion-settings
JS Globals
marin_companion_params
FAQ

Frequently Asked Questions about Marin Companion