Steed Companion Security & Risk Analysis

wordpress.org/plugins/steed-companion

Enhances Steed’s themes with extra functionalities.

0 active installs v1.2.1 PHP + WP 4.4+ Updated Sep 25, 2017
shortcodesteedsteed-companiontallythemeswidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Steed Companion Safe to Use in 2026?

Generally Safe

Score 85/100

Steed Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The steed-companion plugin v1.2.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals no dangerous functions, file operations, or external HTTP requests, and all SQL queries utilize prepared statements. This indicates good development practices in these critical areas.

The primary area of concern lies in the output escaping. With 330 total outputs and only 43% properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data, if not properly handled before being displayed, could be injected into the page and executed by a user's browser.

The vulnerability history is completely clean, with no known CVEs recorded. This, combined with the absence of critical taint flows and the use of prepared statements, suggests a generally secure codebase. However, the unescaped output remains a notable weakness that could be exploited despite the lack of historical vulnerabilities.

Key Concerns

  • Significant percentage of unescaped output
Vulnerabilities
None known

Steed Companion Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Steed Companion Release Timeline

v1.2.1Current
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

Steed Companion Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
189
141 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

43% escaped330 total outputs
Attack Surface

Steed Companion Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionafter_setup_themesteed-companion.php:44
actionadmin_enqueue_scriptssteed-companion.php:60
actionwp_enqueue_scriptssteed-companion.php:71
actionwidgets_initsteed-companion.php:84
actionadmin_enqueue_scriptswidgets\advance-text-widget.php:12
actionadmin_enqueue_scriptswidgets\quote.php:16
actionadmin_enqueue_scriptswidgets\service.php:16
actionadmin_enqueue_scriptswidgets\slider-item-widget.php:16
actionadmin_footer-widgets.phpwidgets\slider-item-widget.php:17
actionadmin_enqueue_scriptswidgets\vCard.php:16
Maintenance & Trust

Steed Companion Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 25, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Steed Companion Developer Profile

TallyThemes

5 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Steed Companion

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/steed-companion/assets/css/steed-companion-admin.css/wp-content/plugins/steed-companion/assets/js/steed-companion-admin.js/wp-content/plugins/steed-companion/assets/css/steed-companion.css/wp-content/plugins/steed-companion/assets/js/steed-companion.js
Script Paths
/wp-content/plugins/steed-companion/assets/js/steed-companion-admin.js/wp-content/plugins/steed-companion/assets/js/steed-companion.js
Version Parameters
steed-companion-admin?ver=steed-companion?ver=

HTML / DOM Fingerprints

CSS Classes
scw-warpscw-warp-inscw-imgscw-img-bgscw-linkscw-contentscw-content-inscw-subtitle+8 more
HTML Comments
<!-- This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.. --><!-- Load the plugin in a safe action ------------------------------------------ --><!-- Load some Admin side CSS and JavaScript files. ------------------------------------------ --><!-- Load some CSS and JavaScript files. ------------------------------------------ -->+2 more
Data Attributes
data-color-pickerdata-iddata-name
JS Globals
SteedCOM_URLSTEEDCOM_URLSTEEDCOM_DRISteedCOM_widget_SliderItemSteedCOM_widget_vCardSteedCOM_widget_quote+2 more
FAQ

Frequently Asked Questions about Steed Companion