SuevaFree Essential Kit Security & Risk Analysis

wordpress.org/plugins/suevafree-essential-kit

Install SuevaFree Essential Kit plugin to enable all features of SuevaFree 3.0 WordPress theme, like 7 custom widgets, three different custom post typ …

200 active installs v1.1.4 PHP + WP 3.5.0+ Updated Nov 20, 2024
custom-fieldcustom-fieldscustom-post-typecustom-post-typesshortcode
91
A · Safe
CVEs total1
Unpatched0
Last CVENov 20, 2024
Safety Verdict

Is SuevaFree Essential Kit Safe to Use in 2026?

Generally Safe

Score 91/100

SuevaFree Essential Kit has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Nov 20, 2024Updated 1yr ago
Risk Assessment

The suevafree-essential-kit plugin version 1.1.4 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no file operations, and no external HTTP requests, which are good indicators. Furthermore, all SQL queries are properly prepared, and there are no identified taint flows with unsanitized paths, suggesting a general effort to avoid common web vulnerabilities. The lack of critical or high-severity historical CVEs is also encouraging.

However, several areas raise concerns. A significant portion of output (45%) is not properly escaped, indicating a potential risk for Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks across all entry points, including the single shortcode identified, is a critical oversight. This means that any authenticated user, regardless of their role, could potentially trigger actions or display content intended for privileged users or requiring specific context. The plugin also has a history of medium-severity vulnerabilities, specifically XSS, which, coupled with the unescaped output and lack of authentication checks, suggests a recurring pattern of input sanitization and output escaping weaknesses that need to be addressed.

In conclusion, while the plugin avoids some severe technical pitfalls like raw SQL or dangerous functions, the high percentage of unescaped output and the complete lack of nonce and capability checks on its entry points present a notable risk, particularly for XSS and privilege escalation. The historical medium-severity XSS vulnerability further emphasizes the need for more robust input validation and output encoding practices.

Key Concerns

  • Unescaped output percentage high
  • No nonce checks on entry points
  • No capability checks on entry points
  • Medium severity vulnerability history
Vulnerabilities
1 published

SuevaFree Essential Kit Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11432medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SuevaFree Essential Kit <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Nov 20, 2024 Patched in 1.1.4 (2d)
Version History

SuevaFree Essential Kit Release Timeline

v1.1.4Current
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.1.01 CVE
v1.0.91 CVE
v1.0.81 CVE
v1.0.71 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

SuevaFree Essential Kit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
284
346 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

55% escaped630 total outputs
Attack Surface

SuevaFree Essential Kit Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[counter] core\shortcodes\counter.php:25
WordPress Hooks 8
actioninitcore\includes\class-custom-post-types.php:18
actionsuevafree_ek_socialsfunctions.php:211
filterthe_contentinit.php:25
actionplugins_loadedinit.php:26
actionwp_enqueue_scriptsinit.php:27
actionwidgets_initinit.php:28
actionadmin_initinit.php:29
actioncustomize_controls_enqueue_scriptsinit.php:30
Maintenance & Trust

SuevaFree Essential Kit Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 20, 2024
PHP min version
Downloads16K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

SuevaFree Essential Kit Developer Profile

alexvtn

76 plugins · 10K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
168 days
View full developer profile
Detection Fingerprints

How We Detect SuevaFree Essential Kit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/suevafree-essential-kit/assets/js/suevafree-ek-scrollReveal.min.js/wp-content/plugins/suevafree-essential-kit/assets/js/suevafree-ek-slick.min.js/wp-content/plugins/suevafree-essential-kit/assets/js/suevafree-ek-jquery.js/wp-content/plugins/suevafree-essential-kit/assets/css/suevafree-ek-slick.css/wp-content/plugins/suevafree-essential-kit/assets/css/suevafree-ek-style.css/wp-content/plugins/suevafree-essential-kit/core/assets/css/suevafree_ek_style.css/wp-content/plugins/suevafree-essential-kit/core/assets/js/suevafree_ek_script.js/wp-content/plugins/suevafree-essential-kit/core/assets/js/suevafree_ek_customize.js
Script Paths
/wp-content/plugins/suevafree-essential-kit/assets/js/suevafree-ek-scrollReveal.min.js/wp-content/plugins/suevafree-essential-kit/assets/js/suevafree-ek-slick.min.js/wp-content/plugins/suevafree-essential-kit/assets/js/suevafree-ek-jquery.js/wp-content/plugins/suevafree-essential-kit/core/assets/js/suevafree_ek_script.js/wp-content/plugins/suevafree-essential-kit/core/assets/js/suevafree_ek_customize.js

HTML / DOM Fingerprints

CSS Classes
suevafree-countersuevafree-circle-countersuevafree-counter-element
Data Attributes
data-count
Shortcode Output
[counter
FAQ

Frequently Asked Questions about SuevaFree Essential Kit