Meks ThemeForest Smart Widget Security & Risk Analysis

wordpress.org/plugins/meks-themeforest-smart-widget

Easily display ThemeForest items inside WordPress widget.

10K active installs v1.6 PHP + WP 3.0+ Updated Jul 23, 2024
affiliateenvatomarketplacethemeforestwidget
92
A · Safe
CVEs total1
Unpatched0
Last CVEApr 26, 2024
Safety Verdict

Is Meks ThemeForest Smart Widget Safe to Use in 2026?

Generally Safe

Score 92/100

Meks ThemeForest Smart Widget has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 26, 2024Updated 1yr ago
Risk Assessment

The static analysis of the 'meks-themeforest-smart-widget' plugin v1.6 reveals a generally good security posture in several key areas. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points significantly limits the plugin's direct attack surface. Furthermore, the adherence to prepared statements for all SQL queries and a high percentage of properly escaped output are commendable practices. The lack of dangerous functions, file operations, and the indication of no taint flows with unsanitized paths also contribute positively to its security. However, a notable concern is the presence of zero nonce checks and zero capability checks, which means that any functionality exposed, even if not directly identified as an entry point, might be susceptible to unauthorized access or actions if an attacker can trigger it. The single external HTTP request, while not inherently a vulnerability, represents a potential dependency on external systems that could be compromised or unavailable, impacting security and functionality. The plugin's vulnerability history, including one known CVE related to Cross-site Scripting, is a significant red flag. While the current version indicates this CVE is patched, the past occurrence of XSS vulnerabilities suggests a history of input validation issues that warrant continued vigilance and thorough auditing of any new or modified code.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • Past XSS vulnerability history
  • Single external HTTP request
Vulnerabilities
1 published

Meks ThemeForest Smart Widget Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-33694medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Meks ThemeForest Smart Widget <= 1.5 - Authenticated (Admin+) Stored Cross-Site Scripting

Apr 26, 2024 Patched in 1.6 (98d)
Version History

Meks ThemeForest Smart Widget Release Timeline

v1.21 CVE
v1.1.91 CVE
v1.1.81 CVE
Code Analysis
Analyzed Mar 16, 2026

Meks ThemeForest Smart Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
151 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

94% escaped161 total outputs
Attack Surface

Meks ThemeForest Smart Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_enqueue_scriptsinc\class-themeforest-widget.php:32
actionadmin_enqueue_scriptsinc\class-themeforest-widget.php:34
actionwidgets_initmeks-themeforest-smart-widget.php:26
actionplugins_loadedmeks-themeforest-smart-widget.php:33
Maintenance & Trust

Meks ThemeForest Smart Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 23, 2024
PHP min version
Downloads306K

Community Trust

Rating100/100
Number of ratings1
Active installs10K
Developer Profile

Meks ThemeForest Smart Widget Developer Profile

Meks

14 plugins · 117K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Meks ThemeForest Smart Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meks-themeforest-smart-widget/css/style.css/wp-content/plugins/meks-themeforest-smart-widget/js/script.js
Script Paths
/wp-content/plugins/meks-themeforest-smart-widget/js/script.js
Version Parameters
meks-themeforest-smart-widget/style.css?ver=meks-themeforest-smart-widget/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
mks_themeforest_widgetmks_themeforest_widget_ulmks_read_more
Data Attributes
data-id="mks_themeforest_widget"data-title="ThemeForest"data-description=""data-items_type="wordpress"data-items_from="user"data-user="meks"+10 more
FAQ

Frequently Asked Questions about Meks ThemeForest Smart Widget