
Options for Twenty Seventeen Security & Risk Analysis
wordpress.org/plugins/options-for-twenty-seventeenAdds powerful customizer options to modify all aspects of the default WordPress theme Twenty Seventeen.
Is Options for Twenty Seventeen Safe to Use in 2026?
Generally Safe
Score 100/100Options for Twenty Seventeen has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'options-for-twenty-seventeen' v2.5.6 exhibits a generally good security posture with strong adherence to best practices in several key areas. The static analysis reveals that all SQL queries are properly prepared, output escaping is excellent with 98% proper handling, and there are no identified dangerous functions, file operations, or external HTTP requests. The presence of a nonce check is also a positive indicator. However, a significant concern is the single AJAX handler that lacks authentication checks, presenting a direct attack vector. While taint analysis found no issues, this unprotected entry point could potentially be exploited if coupled with other vulnerabilities or logic flaws.
The vulnerability history shows one medium-severity CVE recorded in September 2023, which was for Cross-site Scripting. The fact that this vulnerability is currently unpatched is a notable weakness. Although the latest version has resolved this specific CVE, the historical presence of XSS indicates a potential for input sanitization or output escaping flaws to be introduced. The overall security is a mixed bag; strengths lie in coding standards for data handling and output, but the unprotected AJAX endpoint and past vulnerability history warrant careful consideration.
Key Concerns
- AJAX handler without authentication check
- Previously known medium severity CVE
Options for Twenty Seventeen Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Options for Twenty Seventeen <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Options for Twenty Seventeen Code Analysis
Output Escaping
Options for Twenty Seventeen Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 21
Maintenance & Trust
Options for Twenty Seventeen Maintenance & Trust
Maintenance Signals
Community Trust
Options for Twenty Seventeen Alternatives
Customize Twenty Seventeen
customize-twenty-seventeen
Customize Twenty Seventeen theme - add Google Fonts, use new templates and get other options to easily customize your site.
Remove "Powered by WordPress"
remove-powered-by-wp
Removes the WordPress credit on all default WordPress themes and replaces with a widget sidebar for those wanting to customise the theme.
Options for Twenty Twenty-One
options-for-twenty-twenty-one
Adds powerful customizer options to modify all aspects of the default WordPress theme Twenty Twenty-One.
Options for Twenty Twenty
options-for-twenty-twenty
Adds powerful customizer options to modify all aspects of the default WordPress theme Twenty Twenty.
Options for Twenty Nineteen
options-for-twenty-nineteen
Adds powerful customizer options to modify all aspects of the default WordPress theme Twenty Nineteen.
Options for Twenty Seventeen Developer Profile
12 plugins · 43K total installs
How We Detect Options for Twenty Seventeen
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/options-for-twenty-seventeen/js/customizer-preview.js/wp-content/plugins/options-for-twenty-seventeen/css/customizer.css/wp-content/plugins/options-for-twenty-seventeen/js/customizer-preview.jsoptions-for-twenty-seventeen/js/customizer-preview.js?ver=options-for-twenty-seventeen/css/customizer.css?ver=HTML / DOM Fingerprints
ofts-social-links-itemdata-ofts-social-links-styleofts_preview[social-links]