
RWP Companion Security & Risk Analysis
wordpress.org/plugins/rwp-companionA companion plugin for the RWP package used to publish to WordPress with R.
Is RWP Companion Safe to Use in 2026?
Generally Safe
Score 85/100RWP Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of rwp-companion v1.1.0 reveals a strong security posture with no identified attack surface, dangerous functions, unsanitized taint flows, or raw SQL queries. The code demonstrates excellent adherence to security best practices, with 100% of SQL queries using prepared statements and all outputs being properly escaped. The absence of external HTTP requests, file operations, and bundled libraries further minimizes potential security risks.
Furthermore, the vulnerability history shows no recorded CVEs, indicating a lack of publicly known vulnerabilities for this plugin. This suggests a history of secure development or diligent patching by the developers. However, the complete lack of nonce and capability checks across all entry points, while seemingly benign due to the zero attack surface, could become a concern if new entry points are introduced in future versions without these essential security measures.
In conclusion, rwp-companion v1.1.0 currently presents a very low security risk. Its robust static analysis results and clean vulnerability history are significant strengths. The primary, albeit theoretical, weakness lies in the absence of nonce and capability checks, which, while not exploitable in the current version, represents a potential area for future oversight.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
RWP Companion Security Vulnerabilities
RWP Companion Code Analysis
RWP Companion Attack Surface
WordPress Hooks 3
Maintenance & Trust
RWP Companion Maintenance & Trust
Maintenance Signals
Community Trust
RWP Companion Alternatives
Contact Form 7
contact-form-7
Just another contact form plugin. Simple but flexible.
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
RWP Companion Developer Profile
6 plugins · 1K total installs
How We Detect RWP Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rwp-companion/build/tabsets.js/wp-content/plugins/rwp-companion/assets/rmarkdown/tables.css/wp-content/plugins/rwp-companion/build/tabsets.jsHTML / DOM Fingerprints
/wp-json/wp/v2/posts?meta_key=rwp_generated/wp-json/wp/v2/posts?meta_key=rwp_tabset