
OliveWP Companion Security & Risk Analysis
wordpress.org/plugins/olivewp-companionOliveWP Companion plugin enhances the functionality of OliveWP theme. This plugin requires OliveWP theme to be installed.
Is OliveWP Companion Safe to Use in 2026?
Generally Safe
Score 85/100OliveWP Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The olivewp-companion v1.1.2 plugin exhibits a concerning security posture due to a significant lack of authentication checks on its entry points. While the plugin does not appear to have a history of publicly disclosed vulnerabilities, this does not negate the risks introduced by its current codebase. The static analysis reveals one AJAX handler that lacks any form of authentication, presenting a direct pathway for unauthorized actions if this handler performs sensitive operations. The taint analysis, though limited in scope, identified two flows with unsanitized paths, which could potentially lead to vulnerabilities if these paths are exposed to user input. The absence of nonce checks on AJAX handlers is a critical oversight, leaving the plugin susceptible to Cross-Site Request Forgery (CSRF) attacks. Despite the positive signs of using prepared statements for SQL queries and a good percentage of output escaping, these strengths are overshadowed by the critical deficiencies in authentication and input sanitization for its exposed entry points. Therefore, while the plugin has avoided past vulnerabilities, its current implementation poses a notable risk that requires immediate attention.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths
- Missing nonce checks on AJAX
- Missing capability checks
- Partially unescaped output
- Bundled Freemius v1.0 library
OliveWP Companion Security Vulnerabilities
OliveWP Companion Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
OliveWP Companion Attack Surface
AJAX Handlers 1
WordPress Hooks 28
Maintenance & Trust
OliveWP Companion Maintenance & Trust
Maintenance Signals
Community Trust
OliveWP Companion Alternatives
Desert Companion
desert-companion
Desert Companion Enhances Desert Themes with additional functionality.
SpiceBox
spicebox
Enhance Spicethemes WordPress Themes functionality.
Arile Extra
arile-extra
Arile Extra is a companion plugin for ArileWP WordPress theme by ThemeArile.
Widget Disable
wp-widget-disable
Disable sidebar and dashboard widgets with an easy to use interface.
Daddy Plus
daddy-plus
Daddy Plus is a useful plugin for WordPress theme by Themes Daddy.
OliveWP Companion Developer Profile
34 plugins · 63K total installs
How We Detect OliveWP Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/olivewp-companion/admin/owc-script.php/wp-content/plugins/olivewp-companion/inc/control/fonts.php/wp-content/plugins/olivewp-companion/inc/control/sanitization.php/wp-content/plugins/olivewp-companion/inc/trending-post/customizer/customizer-trending-post.php/wp-content/plugins/olivewp-companion/inc/trending-post/olivewp-companion-trending-post.php/wp-content/plugins/olivewp-companion/inc/control/customizer-category-dropdown-custom-control.php/wp-content/plugins/olivewp-companion/inc/control/customizer-taxonomy-dropdown-custom-control.php/wp-content/plugins/olivewp-companion/inc/control/customizer-image-checkbox-custom-control.php+3 more