
Steed Companion Security & Risk Analysis
wordpress.org/plugins/steed-companionEnhances Steed’s themes with extra functionalities.
Is Steed Companion Safe to Use in 2026?
Generally Safe
Score 85/100Steed Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The steed-companion plugin v1.2.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals no dangerous functions, file operations, or external HTTP requests, and all SQL queries utilize prepared statements. This indicates good development practices in these critical areas.
The primary area of concern lies in the output escaping. With 330 total outputs and only 43% properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data, if not properly handled before being displayed, could be injected into the page and executed by a user's browser.
The vulnerability history is completely clean, with no known CVEs recorded. This, combined with the absence of critical taint flows and the use of prepared statements, suggests a generally secure codebase. However, the unescaped output remains a notable weakness that could be exploited despite the lack of historical vulnerabilities.
Key Concerns
- Significant percentage of unescaped output
Steed Companion Security Vulnerabilities
Steed Companion Release Timeline
Steed Companion Code Analysis
Output Escaping
Steed Companion Attack Surface
WordPress Hooks 10
Maintenance & Trust
Steed Companion Maintenance & Trust
Maintenance Signals
Community Trust
Steed Companion Alternatives
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Weaver Xtreme Theme Support
weaverx-theme-support
A useful shortcode and widget collection for Weaver Xtreme
Popularis Extra
popularis-extra
Popularis Extra add extra features to Popularis theme like demo import, widgets, shortcodes or Elementor widgets.
Disable Author Pages
disable-author-pages
Disable the author pages
Weaver Show Posts
show-posts
Show Posts in a Page via shortcode for any theme
Steed Companion Developer Profile
5 plugins · 130 total installs
How We Detect Steed Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/steed-companion/assets/css/steed-companion-admin.css/wp-content/plugins/steed-companion/assets/js/steed-companion-admin.js/wp-content/plugins/steed-companion/assets/css/steed-companion.css/wp-content/plugins/steed-companion/assets/js/steed-companion.js/wp-content/plugins/steed-companion/assets/js/steed-companion-admin.js/wp-content/plugins/steed-companion/assets/js/steed-companion.jssteed-companion-admin?ver=steed-companion?ver=HTML / DOM Fingerprints
scw-warpscw-warp-inscw-imgscw-img-bgscw-linkscw-contentscw-content-inscw-subtitle+8 more<!--
This program is free software; you can redistribute it and/or
modify it under the terms of the GNU General Public License
as published by the Free Software Foundation; either version 2
of the License, or (at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with this program; if not, write to the Free Software
Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA..
--><!--
Load the plugin in a safe action
------------------------------------------
--><!--
Load some Admin side CSS and JavaScript
files.
------------------------------------------
--><!--
Load some CSS and JavaScript
files.
------------------------------------------
-->+2 moredata-color-pickerdata-iddata-nameSteedCOM_URLSTEEDCOM_URLSTEEDCOM_DRISteedCOM_widget_SliderItemSteedCOM_widget_vCardSteedCOM_widget_quote+2 more