
Onix Helper Security & Risk Analysis
wordpress.org/plugins/onix-helper-cpt-cmb-taxonomiesOnix Helper is intended to create Custom Post Types and Custom Taxonomies in a way convenient to you. This plugin suits developers, agencies and priva …
Is Onix Helper Safe to Use in 2026?
Generally Safe
Score 85/100Onix Helper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "onix-helper-cpt-cmb-taxonomies" plugin v1.0.2 exhibits a concerning security posture, primarily due to a significant number of unprotected entry points. While the code demonstrates good practices in other areas, such as the absence of dangerous functions and a high percentage of properly escaped output, the lack of authentication checks on all identified AJAX handlers presents a substantial risk. The plugin has a total of 6 AJAX handlers, and alarmingly, all 6 lack proper authorization checks, meaning any unauthenticated user could potentially interact with these functions. This wide-open attack surface, with 6 unprotected entry points, is the most critical finding. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this clean history should not overshadow the immediate risks posed by the unprotected AJAX handlers. The lack of taint analysis results and the limited number of observed file operations and external HTTP requests suggest that complex attack vectors involving these areas are not present or were not detected in the static analysis. In conclusion, while the plugin avoids common pitfalls like raw SQL queries and has good output escaping, the critical flaw of unprotected AJAX handlers significantly weakens its overall security. Remediation of these unprotected handlers should be the top priority.
Key Concerns
- 6 AJAX handlers without auth checks
- 6 unprotected entry points
Onix Helper Security Vulnerabilities
Onix Helper Code Analysis
Output Escaping
Onix Helper Attack Surface
AJAX Handlers 6
WordPress Hooks 8
Maintenance & Trust
Onix Helper Maintenance & Trust
Maintenance Signals
Community Trust
Onix Helper Alternatives
Naveed Post Types
naveed-post-types
Naveed Post Types is an elegant way to create custom post types and custom taxonomies in WordPress.
ARPCSO Page CPT-Style Organizer
arpcso-page-cpt-style-organizer
Organize Custom Post Types (CPT) and Custom Taxonomies (CT) in pages.
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Essential Content Types
essential-content-types
Essential Content Types allows you to feature the impressive content through different content/post types on your website just the way you want it.
Custom Post Type Widgets
custom-post-type-widgets
Custom Post Type Widgets plugin adds default custom post type widgets.
Onix Helper Developer Profile
1 plugin · 10 total installs
How We Detect Onix Helper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/onix-helper-cpt-cmb-taxonomies/assets/css/style.min.css/wp-content/plugins/onix-helper-cpt-cmb-taxonomies/assets/js/main.js/wp-content/plugins/onix-helper-cpt-cmb-taxonomies/assets/js/callbacks-js.js/wp-content/plugins/onix-helper-cpt-cmb-taxonomies/assets/js/selects-library.js/wp-content/plugins/onix-helper-cpt-cmb-taxonomies/assets/js/admin-top-navigation-panel.js/wp-content/plugins/onix-helper-cpt-cmb-taxonomies/assets/js/meta-fields.js/wp-content/plugins/onix-helper-cpt-cmb-taxonomies/assets/js/fields-manager/front/screen-options.js/wp-content/plugins/onix-helper-cpt-cmb-taxonomies/assets/js/fields-manager/front/box-fields-validation.js+1 morehttps://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta2/css/all.min.cssHTML / DOM Fingerprints
row-right-partoh-field-contentoh-field-additional-contentdata-validation-slugomb_ajax_object