
One Page Express Companion Security & Risk Analysis
wordpress.org/plugins/one-page-express-companionThe One Page Express Companion plugin adds drag and drop page builder functionality to the One Page Express theme.
Is One Page Express Companion Safe to Use in 2026?
Generally Safe
Score 98/100One Page Express Companion has a strong security track record. Known vulnerabilities have been patched promptly.
The one-page-express-companion plugin v1.6.46 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query preparation and output escaping, certain aspects raise concerns. The presence of one unprotected AJAX handler presents a direct attack vector that could be exploited without proper authentication. Despite a relatively low number of entry points, this unprotected handler is a significant weakness.
The vulnerability history shows a past of medium severity issues, specifically related to missing authorization and cross-site scripting. Although there are currently no unpatched vulnerabilities, the recurring nature of these vulnerability types suggests potential underlying coding patterns that might lead to similar issues in the future if not addressed comprehensively. The plugin's static analysis reveals no critical or high-severity taint flows, which is a positive sign, but the unprotected AJAX handler remains a notable risk.
In conclusion, the plugin has strengths in its secure handling of SQL and output, but the unprotected AJAX endpoint is a critical flaw that demands immediate attention. The history of medium vulnerabilities, though patched, warrants vigilance. Addressing the unprotected AJAX handler is paramount to improving the plugin's overall security.
Key Concerns
- Unprotected AJAX handler
- Past medium severity vulnerabilities (Missing Auth, XSS)
One Page Express Companion Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
One Page Express Companion <= 1.6.43 - Missing Authorization
One Page Express Companion <= 1.6.37 - Authenticated (Contributor+) Stored Cross-Site Scripting via one_page_express_contact_form Shortcode
One Page Express Companion Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
One Page Express Companion Attack Surface
AJAX Handlers 6
Shortcodes 3
WordPress Hooks 61
Maintenance & Trust
One Page Express Companion Maintenance & Trust
Maintenance Signals
Community Trust
One Page Express Companion Alternatives
No alternatives data available yet.
One Page Express Companion Developer Profile
3 plugins · 76K total installs
How We Detect One Page Express Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/one-page-express-companion/assets/js/customizer/customizer-base.js/wp-content/plugins/one-page-express-companion/assets/js/customizer/multi-image-control.js/wp-content/plugins/one-page-express-companion/assets/js/customizer/row-list-control.js/wp-content/plugins/one-page-express-companion/vendor/framework/assets/js/app.js/wp-content/plugins/one-page-express-companion/vendor/framework/assets/js/customizer/app.jsone-page-express-companion/style.css?ver=one-page-express-companion/script.js?ver=HTML / DOM Fingerprints
cp-multi-image-managercp-multi-image-itemrows-listavailable-itemalready-in-pagelist-holderimage-holderavailable-item-hover-button+3 more<!-- Section is already in page --><!-- Pro Only -->data-type="cp-multi-image-manager"data-mindata-maxdata-setting-linkdata-namedata-selection+5 morecpMultiImageTextsCP_Customizer.openMediaBrowsercp_preset_changer_