
Stepfox Looks Security & Risk Analysis
wordpress.org/plugins/stepfox-looksEnhances the block editor with responsive controls, custom blocks, and extensions for modern magazine and news sites.
Is Stepfox Looks Safe to Use in 2026?
Generally Safe
Score 100/100Stepfox Looks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "stepfox-looks" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests, combined with a 100% usage of prepared statements for SQL queries, are excellent security practices. The plugin also demonstrates a good understanding of WordPress security by implementing nonce checks and capability checks for its entry points, with all AJAX handlers protected.
The taint analysis revealed no flows with unsanitized paths, indicating that data is likely handled securely. The high percentage of properly escaped output (87%) is also a positive sign, minimizing the risk of cross-site scripting (XSS) vulnerabilities. The lack of any known CVEs in its history further strengthens this positive assessment, suggesting a history of secure development or a lack of targeted exploits.
While the plugin demonstrates many strengths, the relatively low number of nonce and capability checks (8 and 3 respectively) compared to the number of AJAX handlers (4) could be a minor area for scrutiny if the logic within those handlers is complex or handles sensitive data. However, given that all AJAX handlers are reported as protected, this is a minor observation. Overall, "stepfox-looks" v1.0.0 appears to be a secure plugin with robust development practices.
Key Concerns
- Low number of capability checks for AJAX handlers
- Unescaped output detected
Stepfox Looks Security Vulnerabilities
Stepfox Looks Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Stepfox Looks Attack Surface
AJAX Handlers 4
WordPress Hooks 44
Maintenance & Trust
Stepfox Looks Maintenance & Trust
Maintenance Signals
Community Trust
Stepfox Looks Alternatives
Custom Fields for Gutenberg
custom-fields-gutenberg
Restores the Custom Field meta box for the Gutenberg Block Editor.
Visibility Controls for Editor Blocks
visibility-controls-for-editor-blocks
Easily hide or show Gutenberg blocks on mobile, tablet, and desktop devices using customizable breakpoints for responsive design.
Tabs Block
tabs-block
Tabs Block is a simple plugin that adds a Gutenberg block for adding Tabs content to your posts and pages.
Blockera Site Builder – Responsive Blocks, Block States, and everything Gutenberg is missing
blockera
Blockera Site Builder is transforming the block editor into a powerful page builder by adding responsive blocks, block states, and more.
Gutenwave Blocks – Gutenberg Page Builder Blocks for Block Editor & FSE
gutenwave-blocks
Build stunning websites with Gutenberg. Free responsive blocks, starter templates & full site editing support in one lightweight plugin.
Stepfox Looks Developer Profile
1 plugin · 30 total installs
How We Detect Stepfox Looks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stepfox-looks/blocks/metafield-block/metafield_block.php/wp-content/plugins/stepfox-looks/blocks/load-more/load-more.php/wp-content/plugins/stepfox-looks/blocks/navigation-mega/navigation-mega.php/wp-content/plugins/stepfox-looks/extensions/responsive/responsive.php/wp-content/plugins/stepfox-looks/extensions/social-share/social-share.php/wp-content/plugins/stepfox-looks/extensions/post-template-fallback/post-template-fallback.php/wp-content/plugins/stepfox-looks/extensions/cover-block-extension/cover-block-extension.php/wp-content/plugins/stepfox-looks/extensions/post-template-allow-template-part/post-template-allow-template-part.php+1 moreHTML / DOM Fingerprints
wp-block-coverstepfox_looksSTEPFOX_LOOKS_VERSIONSTEPFOX_LOOKS_PATHSTEPFOX_LOOKS_URL