
Oneto Companion Security & Risk Analysis
wordpress.org/plugins/oneto-companionEnhance Oneto WordPress Themes Functionality.
Is Oneto Companion Safe to Use in 2026?
Generally Safe
Score 92/100Oneto Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The oneto-companion v1.1 plugin exhibits a generally good security posture with a few notable concerns. Its static analysis reveals an extremely small attack surface, with only one entry point identified. The plugin also demonstrates strong practices by utilizing prepared statements for all SQL queries and properly escaping the vast majority (97%) of its output. The absence of file operations, external HTTP requests, and any identified dangerous functions further contributes to its positive security profile. Furthermore, the plugin has no recorded vulnerability history, indicating a consistent track record of security awareness or luck.
However, the presence of a single AJAX handler without authentication checks is a significant concern. This unprotected entry point could be a potential vector for malicious activity if not properly secured within the application's logic. While no critical or high-severity taint flows were found, the lack of nonce checks on the AJAX handler amplifies the risk associated with this unprotected entry point. The complete absence of capability checks also means that the plugin doesn't leverage WordPress's built-in role and permission system to restrict access to its functionality, which could be a missed security opportunity.
Key Concerns
- AJAX handler without auth checks
- No nonce checks on AJAX handler
- No capability checks
Oneto Companion Security Vulnerabilities
Oneto Companion Code Analysis
Output Escaping
Oneto Companion Attack Surface
AJAX Handlers 1
WordPress Hooks 25
Maintenance & Trust
Oneto Companion Maintenance & Trust
Maintenance Signals
Community Trust
Oneto Companion Alternatives
Desert Companion
desert-companion
Desert Companion Enhances Desert Themes with additional functionality.
Arile Extra
arile-extra
Arile Extra is a companion plugin for ArileWP WordPress theme by ThemeArile.
Arile Super
arile-super
Arile Super is a companion plugin for Aasta WordPress theme by ThemeArile.
Clever Fox
clever-fox
Clever Fox plugin to enhance the functionality of free themes made by Nayra Themes.
SpiceBox
spicebox
Enhance Spicethemes WordPress Themes functionality.
Oneto Companion Developer Profile
72 plugins · 54K total installs
How We Detect Oneto Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oneto-companion/inc/oneto/customizer/customizer-page-editor/css/oneto-page-editor.css/wp-content/plugins/oneto-companion/inc/oneto/customizer/customizer-page-editor/js/oneto-text-editor.js/wp-content/plugins/oneto-companion/inc/oneto/customizer/customizer-page-editor/js/oneto-update-controls.js/wp-content/plugins/oneto-companion/inc/oneto/assets/css/animate.css/wp-content/plugins/oneto-companion/inc/oneto/assets/css/owl.carousel.min.css/wp-content/plugins/oneto-companion/inc/oneto/assets/css/oneto.css/wp-content/plugins/oneto-companion/inc/oneto/assets/js/owl.carousel.min.js/wp-content/plugins/oneto-companion/inc/oneto/assets/js/custom.js/wp-content/plugins/oneto-companion/inc/oneto/customizer/customizer-page-editor/js/oneto-text-editor.js/wp-content/plugins/oneto-companion/inc/oneto/customizer/customizer-page-editor/js/oneto-update-controls.js/wp-content/plugins/oneto-companion/inc/oneto/assets/js/owl.carousel.min.js/wp-content/plugins/oneto-companion/inc/oneto/assets/js/custom.jsoneto_text_editor_css?ver=oneto_text_editor?ver=oneto_controls_script?ver=animate.css?ver=owl.carousel.min.css?ver=oneto.css?ver=owl.carousel.min.js?ver=custom.js?ver=HTML / DOM Fingerprints
edit-content-buttoneditorfieldWPEditorWidget