
Neville Extensions Security & Risk Analysis
wordpress.org/plugins/neville-extensionsAdds front page sections (Instagram, Ads), a post title design option and other extensions to Neville WordPress theme.
Is Neville Extensions Safe to Use in 2026?
Generally Safe
Score 85/100Neville Extensions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'neville-extensions' v1.0.0 plugin exhibits a generally good security posture, with no recorded historical vulnerabilities. The static analysis shows a negligible attack surface, with all identified entry points correctly protected by authentication checks. The code also demonstrates strong adherence to secure coding practices regarding SQL queries and output escaping, with 100% of SQL queries utilizing prepared statements and a high percentage of outputs being properly escaped. The presence of nonce checks and capability checks further enhances its security. However, there is one notable concern: the use of the `preg_replace` function with the `/e` modifier is a known source of potential remote code execution vulnerabilities if not handled with extreme caution and proper sanitization. While the taint analysis found no issues, this specific function usage represents a potential risk that warrants attention. The absence of any past vulnerabilities is a positive indicator, suggesting diligent development or a lack of targeted exploits, but it does not completely negate the risks identified in the code signals.
Key Concerns
- Use of preg_replace with /e modifier
- 8% of output not properly escaped
Neville Extensions Security Vulnerabilities
Neville Extensions Release Timeline
Neville Extensions Code Analysis
Dangerous Functions Found
Output Escaping
Neville Extensions Attack Surface
WordPress Hooks 40
Maintenance & Trust
Neville Extensions Maintenance & Trust
Maintenance Signals
Community Trust
Neville Extensions Alternatives
No alternatives data available yet.
Neville Extensions Developer Profile
6 plugins · 2K total installs
How We Detect Neville Extensions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/neville-extensions/assets/css/admin.css/wp-content/plugins/neville-extensions/assets/js/admin.js/wp-content/plugins/neville-extensions/assets/js/instagram.js/wp-content/plugins/neville-extensions/assets/js/admin.js/wp-content/plugins/neville-extensions/assets/js/instagram.jsneville-extensions/assets/css/admin.css?ver=neville-extensions/assets/js/admin.js?ver=HTML / DOM Fingerprints
nevillex-instagram-widgetnevillex-instagarm-connectedid="nevillex-instagram-settings_access-token"nevillex_instagram_admin