
Matcha Extra Security & Risk Analysis
wordpress.org/plugins/matcha-extraUsed for adding extra features to WP Matcha Themes.
Is Matcha Extra Safe to Use in 2026?
Generally Safe
Score 100/100Matcha Extra has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "matcha-extra" v1.0.3 plugin exhibits a generally good security posture with some notable exceptions. The plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for the vast majority of its SQL queries and properly escaping most of its output. The absence of file operations and external HTTP requests further reduces potential attack vectors. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of responsible development and maintenance.
However, a significant concern arises from the presence of an unprotected AJAX handler. This creates a direct entry point for unauthenticated attackers to potentially interact with the plugin's functionality, which could lead to various security issues if not handled with extreme care. While the plugin has a nonce check, it's only present for one of the entry points, leaving the other susceptible. The lack of capability checks on any entry points further exacerbates this risk.
In conclusion, while "matcha-extra" v1.0.3 shows strengths in data handling and output sanitization, the unprotected AJAX handler represents a critical weakness. Addressing this vulnerability is paramount to improving the plugin's overall security. The plugin's clean vulnerability history is a positive indicator, but it does not negate the risks posed by actively exploitable code flaws.
Key Concerns
- Unprotected AJAX handler
- No capability checks on entry points
- Only 1 nonce check for 2 AJAX handlers
Matcha Extra Security Vulnerabilities
Matcha Extra Code Analysis
SQL Query Safety
Output Escaping
Matcha Extra Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Matcha Extra Maintenance & Trust
Maintenance Signals
Community Trust
Matcha Extra Alternatives
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Weaver Xtreme Theme Support
weaverx-theme-support
A useful shortcode and widget collection for Weaver Xtreme
Bonkers Addons
bonkers-addons
This plugins adds several options in the customizer to use with your theme.
Steed Companion
steed-companion
Enhances Steed’s themes with extra functionalities.
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Matcha Extra Developer Profile
2 plugins · 0 total installs
How We Detect Matcha Extra
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/matcha-extra/inc/pawfect/customizer/js/customizer.js/wp-content/plugins/matcha-extra/inc/pawfect/customizer/css/customizer.css/wp-content/plugins/matcha-extra/inc/pawfect/customizer/js/customizer.jsmatcha-extra/inc/pawfect/customizer/js/customizer.js?ver=matcha-extra/inc/pawfect/customizer/css/customizer.css?ver=HTML / DOM Fingerprints
repeater-wrapperrepeater-itemsrepeater-itemrepeater-item-headerrepeater-item-titlerepeater-item-togglerepeater-item-removerepeater-item-content+6 moredata-fieldMatcha_Extra_Repeater_Control