Storefront Pro Skins Security & Risk Analysis

wordpress.org/plugins/storefront-pro-skins

Storefront Pro Skins

100 active installs v1.0.0 PHP + WP 4.1.0+ Updated Jan 24, 2022
pootlepressstorefrontstorefront-protheme-customizerwordpress-customizer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Storefront Pro Skins Safe to Use in 2026?

Generally Safe

Score 85/100

Storefront Pro Skins has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The Storefront Pro Skins plugin version 1.0.0 exhibits a concerning security posture primarily due to its unprotected AJAX handler. While the plugin does not appear to utilize dangerous functions, perform file operations, or make external HTTP requests, and its SQL queries are prepared, the presence of an AJAX endpoint accessible without any authentication or capability checks creates a significant attack vector. The absence of proper output escaping for all identified outputs further exacerbates this risk, as it could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly into the page.

The plugin's vulnerability history is currently clean, with no recorded CVEs. This is a positive indicator, suggesting that past development may have been relatively secure or that the plugin has not been a target for exploitation. However, the static analysis reveals critical weaknesses that could easily be exploited, especially given the lack of taint analysis data, which prevents a deeper understanding of potential data flow vulnerabilities.

In conclusion, while the absence of dangerous functions and external requests, along with prepared SQL, are strengths, the unprotected AJAX entry point and pervasive unescaped output present substantial risks. The plugin needs immediate attention to secure its AJAX handler and ensure all output is properly escaped to mitigate potential XSS and other injection attacks.

Key Concerns

  • AJAX handler without authentication
  • All outputs unescaped
  • No nonce checks on AJAX
Vulnerabilities
None known

Storefront Pro Skins Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Storefront Pro Skins Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface
1 unprotected

Storefront Pro Skins Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_sfp_clear_skinsstorefront-pro-skins.php:109
WordPress Hooks 3
actionafter_setup_themestorefront-pro-skins.php:78
actioncustomize_controls_print_footer_scriptsstorefront-pro-skins.php:108
actionwp_enqueue_scriptsstorefront-pro-skins.php:120
Maintenance & Trust

Storefront Pro Skins Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.0
Last updatedJan 24, 2022
PHP min version
Downloads8K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Storefront Pro Skins Developer Profile

pootlepress

9 plugins · 1K total installs

82
trust score
Avg Security Score
83/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Storefront Pro Skins

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/storefront-pro-skins/assets/admin.css/wp-content/plugins/storefront-pro-skins/assets/admin.js
Script Paths
/wp-content/plugins/storefront-pro-skins/assets/admin.js
Version Parameters
storefront-pro-skins/assets/admin.css?ver=storefront-pro-skins/assets/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
sfp-skins-overlaysfp-skins-dialogsfp-skins-noticesfp-skins-apply-confirmsfps-connectingsfps-user-actionssfps-managesfps-new-user+2 more
HTML Comments
Plugin admin classPlugin public classStorefront Pro Skins main classInstance+29 more
Data Attributes
onclickid="sfp-skins-overlay"style="display: none;"id="sfp-skins-dialog"class="dashicons dashicons-no"onclick="sfpSkins.closeSaveDlg()"+34 more
JS Globals
sfpSkinssfps
FAQ

Frequently Asked Questions about Storefront Pro Skins