
Show Current Template Security & Risk Analysis
wordpress.org/plugins/show-current-templateA WordPress plugin which shows the current template file name, the current theme name and included template files' name in the tool bar.
Is Show Current Template Safe to Use in 2026?
Generally Safe
Score 100/100Show Current Template has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'show-current-template' plugin version 0.5.4 demonstrates a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code analysis indicates a clean codebase with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The taint analysis also found no vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of its security over time. The plugin's strengths lie in its minimal entry points and diligent use of secure coding practices for the code that does exist.
While the static analysis and vulnerability history are reassuring, a notable concern is the complete lack of capability checks and nonce checks. Although the attack surface is currently zero, any future addition of entry points without these fundamental WordPress security mechanisms could introduce significant vulnerabilities. The current version is secure due to its limited functionality and attack surface, but this lack of built-in security checks is a potential weakness for future development or if its functionality were to expand without addressing this oversight.
Key Concerns
- Missing capability checks
- Missing nonce checks
Show Current Template Security Vulnerabilities
Show Current Template Code Analysis
Output Escaping
Show Current Template Attack Surface
WordPress Hooks 4
Maintenance & Trust
Show Current Template Maintenance & Trust
Maintenance Signals
Community Trust
Show Current Template Alternatives
What The File
what-the-file
What The File is the best tool to find out what template parts are used to display the page you're currently viewing!
which template file
which-template-file
Show the name of the php file of your theme used to display the current page.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Show Current Template Developer Profile
95 plugins · 237K total installs
How We Detect Show Current Template
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/show-current-template/css/style.css/wp-content/plugins/show-current-template/css/style-old.css/wp-content/plugins/show-current-template/assets/js/replace.js/wp-content/plugins/show-current-template/assets/js/replace.jsshow-current-template/css/style.css?ver=show-current-template/assets/js/replace.js?ver=HTML / DOM Fingerprints
show-template-name