Stepfox Looks Security & Risk Analysis

wordpress.org/plugins/stepfox-looks

Enhances the block editor with responsive controls, custom blocks, and extensions for modern magazine and news sites.

30 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Sep 13, 2025
blockscustom-fieldsgutenbergload-moreresponsive
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Stepfox Looks Safe to Use in 2026?

Generally Safe

Score 100/100

Stepfox Looks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "stepfox-looks" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests, combined with a 100% usage of prepared statements for SQL queries, are excellent security practices. The plugin also demonstrates a good understanding of WordPress security by implementing nonce checks and capability checks for its entry points, with all AJAX handlers protected.

The taint analysis revealed no flows with unsanitized paths, indicating that data is likely handled securely. The high percentage of properly escaped output (87%) is also a positive sign, minimizing the risk of cross-site scripting (XSS) vulnerabilities. The lack of any known CVEs in its history further strengthens this positive assessment, suggesting a history of secure development or a lack of targeted exploits.

While the plugin demonstrates many strengths, the relatively low number of nonce and capability checks (8 and 3 respectively) compared to the number of AJAX handlers (4) could be a minor area for scrutiny if the logic within those handlers is complex or handles sensitive data. However, given that all AJAX handlers are reported as protected, this is a minor observation. Overall, "stepfox-looks" v1.0.0 appears to be a secure plugin with robust development practices.

Key Concerns

  • Low number of capability checks for AJAX handlers
  • Unescaped output detected
Vulnerabilities
None known

Stepfox Looks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Stepfox Looks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
14 prepared
Unescaped Output
26
177 escaped
Nonce Checks
8
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared14 total queries

Output Escaping

87% escaped203 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
stepfox_load_more_posts_callback (blocks\load-more\load-more.php:72)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Stepfox Looks Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_stepfox_clear_cacheadmin\class-stepfox-admin.php:20
authwp_ajax_stepfox_clear_single_cacheadmin\class-stepfox-admin.php:21
authwp_ajax_stepfox_looks_load_moreblocks\load-more\load-more.php:205
noprivwp_ajax_stepfox_looks_load_moreblocks\load-more\load-more.php:206
WordPress Hooks 44
actionadmin_menuadmin\class-stepfox-admin.php:17
actionadmin_initadmin\class-stepfox-admin.php:18
actionadmin_enqueue_scriptsadmin\class-stepfox-admin.php:19
actionwp_loadedblocks\load-more\load-more.php:4
actioninitblocks\load-more\load-more.php:37
actionwp_enqueue_scriptsblocks\load-more\load-more.php:69
actionwp_print_footer_scriptsblocks\load-more\load-more.php:267
filterrender_blockblocks\load-more\load-more.php:371
actionwp_headblocks\metafield-block\metafield_block.php:385
actioninitblocks\metafield-block\metafield_block.php:390
actioninitblocks\navigation-mega\navigation-mega.php:194
actionenqueue_block_editor_assetsextensions\cover-block-extension\cover-block-extension.php:36
filterrender_block_core/coverextensions\cover-block-extension\cover-block-extension.php:62
actionenqueue_block_editor_assetsextensions\post-template-allow-template-part\post-template-allow-template-part.php:36
actionenqueue_block_editor_assetsextensions\post-template-fallback\post-template-fallback.php:41
filterrender_blockextensions\post-template-fallback\post-template-fallback.php:75
filterrender_blockextensions\post-template-fallback\post-template-fallback.php:99
filterrender_blockextensions\post-template-fallback\post-template-fallback.php:133
actioninitextensions\post-template-fallback\post-template-fallback.php:177
filterrender_block_dataextensions\post-template-fallback\post-template-fallback.php:223
filterget_the_termsextensions\post-template-fallback\post-template-fallback.php:234
filterquery_block_get_query_varsextensions\post-template-fallback\post-template-fallback.php:240
filterrender_block_core/template-partextensions\post-template-fallback\post-template-fallback.php:265
filterregister_block_type_argsextensions\responsive\responsive-attrs.php:10
actionwp_enqueue_scriptsextensions\responsive\responsive-cache.php:116
actionsave_postextensions\responsive\responsive-cache.php:158
actionwp_update_nav_menuextensions\responsive\responsive-cache.php:159
actionswitch_themeextensions\responsive\responsive-cache.php:160
actioncustomize_save_afterextensions\responsive\responsive-cache.php:161
actionrest_after_save_wp_templateextensions\responsive\responsive-cache.php:162
actionrest_after_save_wp_template_partextensions\responsive\responsive-cache.php:163
actionadmin_noticesextensions\responsive\responsive-cache.php:168
actionadmin_initextensions\responsive\responsive-cache.php:174
filterrender_blockextensions\responsive\responsive-dom.php:301
actionenqueue_block_editor_assetsextensions\responsive\responsive-editor.php:64
actionenqueue_block_editor_assetsextensions\responsive\responsive.php:191
actionenqueue_block_assetsextensions\responsive\responsive.php:208
actionwp_enqueue_scriptsextensions\responsive\responsive.php:230
actionenqueue_block_editor_assetsextensions\social-share\social-share.php:36
filterregister_block_type_argsextensions\social-share\social-share.php:57
filterrender_blockextensions\social-share\social-share.php:122
actionplugins_loadedstepfox-looks.php:48
actionwp_loadedstepfox-looks.php:49
filterwp_get_attachment_image_attributesstepfox-looks.php:202
Maintenance & Trust

Stepfox Looks Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedSep 13, 2025
PHP min version7.4
Downloads211

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Stepfox Looks Developer Profile

StepFox Themes

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Stepfox Looks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stepfox-looks/blocks/metafield-block/metafield_block.php/wp-content/plugins/stepfox-looks/blocks/load-more/load-more.php/wp-content/plugins/stepfox-looks/blocks/navigation-mega/navigation-mega.php/wp-content/plugins/stepfox-looks/extensions/responsive/responsive.php/wp-content/plugins/stepfox-looks/extensions/social-share/social-share.php/wp-content/plugins/stepfox-looks/extensions/post-template-fallback/post-template-fallback.php/wp-content/plugins/stepfox-looks/extensions/cover-block-extension/cover-block-extension.php/wp-content/plugins/stepfox-looks/extensions/post-template-allow-template-part/post-template-allow-template-part.php+1 more

HTML / DOM Fingerprints

CSS Classes
wp-block-cover
Data Attributes
stepfox_looks
JS Globals
STEPFOX_LOOKS_VERSIONSTEPFOX_LOOKS_PATHSTEPFOX_LOOKS_URL
FAQ

Frequently Asked Questions about Stepfox Looks