
Sunset Core Security & Risk Analysis
wordpress.org/plugins/sunset-coreThis plugin was made for the My Sunset Theme and adds extra functionality to it.
Is Sunset Core Safe to Use in 2026?
Generally Safe
Score 92/100Sunset Core has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sunset-core" v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for SQL queries, and 100% proper output escaping are commendable practices that significantly reduce the risk of common vulnerabilities. Furthermore, the plugin demonstrates a commitment to security by implementing capability checks for its functionality.
However, there are a few areas that warrant attention. The plugin does not implement nonce checks, which is a common security mechanism to prevent Cross-Site Request Forgery (CSRF) attacks. While the static analysis reported zero unprotected entry points, the lack of nonce checks on its two shortcode entry points represents a potential weakness that could be exploited in conjunction with other vulnerabilities or social engineering tactics.
The plugin's vulnerability history is also a positive indicator, with no known CVEs recorded. This suggests a history of responsible development and security awareness. In conclusion, "sunset-core" v1.0.1 is a relatively secure plugin, but the omission of nonce checks is a notable concern that slightly diminishes its otherwise robust security profile.
Key Concerns
- Missing nonce checks on shortcodes
Sunset Core Security Vulnerabilities
Sunset Core Code Analysis
Output Escaping
Sunset Core Attack Surface
Shortcodes 2
WordPress Hooks 19
Maintenance & Trust
Sunset Core Maintenance & Trust
Maintenance Signals
Community Trust
Sunset Core Developer Profile
7 plugins · 2K total installs
How We Detect Sunset Core
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sunset-core/dist/blocks.style.build.css/wp-content/plugins/sunset-core/dist/blocks.build.js/wp-content/plugins/sunset-core/dist/blocks.editor.build.css/wp-content/plugins/sunset-core/dist/front.build.js/wp-content/plugins/sunset-core/dist/blocks.build.js/wp-content/plugins/sunset-core/dist/front.build.jsHTML / DOM Fingerprints
wp-block-sunset-block-sunset-coredata-block="{ "name": "sunset/block-sunset-core", "sunsetCoreGlobal