
Pando Extra Security & Risk Analysis
wordpress.org/plugins/pando-extraOverview This is a companion plugin for the PandoWP theme, it add all functionalities that are plugin-territory to the PandoWP theme.
Is Pando Extra Safe to Use in 2026?
Generally Safe
Score 85/100Pando Extra has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pando-extra" plugin version 1.1 exhibits a generally good security posture, with strong adherence to secure coding practices. The plugin excels in output escaping, with 97% of outputs properly handled, and uses prepared statements for 75% of its SQL queries. The absence of file operations and external HTTP requests further mitigates common attack vectors. Furthermore, its vulnerability history is clean, with no known CVEs recorded, suggesting a well-maintained codebase.
However, a notable concern arises from the attack surface analysis, which reveals one AJAX handler lacking authentication checks. While taint analysis shows no immediate critical or high-severity issues, this unprotected entry point represents a potential avenue for attackers to interact with the plugin without proper authorization. The presence of multiple AJAX handlers (four total) amplifies this concern, as it increases the potential for further vulnerabilities if not diligently secured.
In conclusion, "pando-extra" v1.1 is largely secure, demonstrating good development practices. The primary weakness lies in the single unprotected AJAX endpoint. Addressing this specific vulnerability would significantly enhance the plugin's overall security. The lack of historical vulnerabilities is a positive indicator, but vigilance remains crucial, especially for newly discovered weaknesses or when implementing new features.
Key Concerns
- Unprotected AJAX handler
Pando Extra Security Vulnerabilities
Pando Extra Release Timeline
Pando Extra Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Pando Extra Attack Surface
AJAX Handlers 4
Shortcodes 3
WordPress Hooks 34
Maintenance & Trust
Pando Extra Maintenance & Trust
Maintenance Signals
Community Trust
Pando Extra Alternatives
Mesmerize Companion
mesmerize-companion
The Mesmerize Companion plugin adds drag and drop page builder functionality to the Mesmerize theme.
Clever Fox
clever-fox
Clever Fox plugin to enhance the functionality of free themes made by Nayra Themes.
Desert Companion
desert-companion
Desert Companion Enhances Desert Themes with additional functionality.
Arile Extra
arile-extra
Arile Extra is a companion plugin for ArileWP WordPress theme by ThemeArile.
One Page Express Companion
one-page-express-companion
The One Page Express Companion plugin adds drag and drop page builder functionality to the One Page Express theme.
Pando Extra Developer Profile
3 plugins · 10K total installs
How We Detect Pando Extra
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pando-extra/css/metabox.css/wp-content/plugins/pando-extra/inc/meta-box/inc/about/js/script.js/wp-content/plugins/pando-extra/inc/meta-box/js/show-hide.js/wp-content/plugins/pando-extra/inc/meta-box/js/autocomplete.jspando-extra/css/metabox.css?ver=meta-box/meta-box.php?ver=meta-box-show-hide/js/show-hide.js?ver=meta-box/js/autocomplete.js?ver=HTML / DOM Fingerprints
rwmb-show-hidedata-showdata-excludeRWMB_Autocomplete