
MyStem Extra Security & Risk Analysis
wordpress.org/plugins/mystem-extraThis plugin helps you to add extra options to WordPress theme MyStem.
Is MyStem Extra Safe to Use in 2026?
Generally Safe
Score 85/100MyStem Extra has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mystem-extra plugin v1.1 presents a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a significant strength. The plugin also demonstrates an understanding of WordPress security by utilizing prepared statements for its SQL queries. However, several areas warrant attention. The percentage of properly escaped output is below ideal at 58%, indicating a potential for cross-site scripting (XSS) vulnerabilities, especially given the 9 shortcodes which represent a considerable attack surface. The complete lack of nonce checks and the low number of capability checks, despite the presence of shortcodes, suggest that the plugin may not be adequately protecting its entry points from unauthorized access or manipulation. The vulnerability history is clean, which is positive, but this does not negate the risks identified in the code analysis. The plugin has a solid foundation, but further hardening is recommended to address potential output escaping and authentication weaknesses.
Key Concerns
- Insufficient output escaping (58%)
- Lack of nonce checks
- Limited capability checks (2)
MyStem Extra Security Vulnerabilities
MyStem Extra Release Timeline
MyStem Extra Code Analysis
Output Escaping
MyStem Extra Attack Surface
Shortcodes 9
WordPress Hooks 24
Maintenance & Trust
MyStem Extra Maintenance & Trust
Maintenance Signals
Community Trust
MyStem Extra Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
MyStem Extra Developer Profile
26 plugins · 98K total installs
How We Detect MyStem Extra
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mystem-extra/category/assets/css/style.css/wp-content/plugins/mystem-extra/category/assets/js/taxonomy.js/wp-content/plugins/mystem-extra/category/assets/js/taxonomy.jsHTML / DOM Fingerprints
iconpickercolor-picker-fieldname="mystem_cat_meta[icon_field]"name="mystem_cat_meta[icon_color]"name="mystem_cat_meta[cat_template]"name="mystem_cat_meta[hide_header]"name="mystem_cat_meta[number_posts]"mystem_fontawesome_icons