
Surplus Essentials Security & Risk Analysis
wordpress.org/plugins/surplus-essentialsSurplus Essentials provides necessary features to extend WordPress functionality and for better blogging experience. It also allows you to add and man …
Is Surplus Essentials Safe to Use in 2026?
Generally Safe
Score 85/100Surplus Essentials has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "surplus-essentials" plugin v1.0.3 exhibits a generally strong security posture based on the provided static analysis. The plugin has no recorded vulnerabilities (CVEs), suggesting a history of secure development or diligent patching. The code analysis reveals a clean codebase with no dangerous functions, no file operations, and no external HTTP requests. Notably, all SQL queries are prepared, and a high percentage (87%) of output is properly escaped, minimizing the risk of common injection and XSS vulnerabilities. The absence of any taint analysis findings further reinforces this positive outlook.
Key Concerns
- No Nonce Checks
- No Capability Checks
- Bundled Libraries (Select2, jQuery)
- Lower percentage of output escaping (87%)
Surplus Essentials Security Vulnerabilities
Surplus Essentials Release Timeline
Surplus Essentials Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Surplus Essentials Attack Surface
WordPress Hooks 57
Maintenance & Trust
Surplus Essentials Maintenance & Trust
Maintenance Signals
Community Trust
Surplus Essentials Alternatives
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Custom Post Type Widgets
custom-post-type-widgets
Custom Post Type Widgets plugin adds default custom post type widgets.
WPSHARE247 Elementor Addons
wpshare247-elementor-addons
Widgets (Wpshare247 Addons) for Elementor. Wpshare247 Addons for Elementor plugin includes widgets and addons like Blog Post, Products, Post, Page and …
Custom Post Type Recent Entries Widget
cpt-recent-entries-widgets
Display a list of the most recent "Custom Post Type" entries in the WordPress widgets.
LabTheme Companion
labtheme-companion
The plugin generates multiple custom post types and number of exclusive widgets which are needed for wordpress theme developed by labtheme
Surplus Essentials Developer Profile
1 plugin · 10 total installs
How We Detect Surplus Essentials
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/surplus-essentials/admin/css/jquery-ui-fresh.min.css/wp-content/plugins/surplus-essentials/admin/css/surplus-essentials-admin.css/wp-content/plugins/surplus-essentials/admin/css/chosen.min.css/wp-content/plugins/surplus-essentials/admin/css/jquery.timepicker.min.css/wp-content/plugins/surplus-essentials/admin/js/jquery.timepicker.min.js/wp-content/plugins/surplus-essentials/admin/js/surplus-essentials-admin.js/wp-content/plugins/surplus-essentials/admin/js/chosen.jquery.min.js/wp-content/plugins/surplus-essentials/admin/js/all.min.js+1 more/wp-content/plugins/surplus-essentials/admin/js/jquery.timepicker.min.js/wp-content/plugins/surplus-essentials/admin/js/surplus-essentials-admin.js/wp-content/plugins/surplus-essentials/admin/js/chosen.jquery.min.js/wp-content/plugins/surplus-essentials/admin/js/all.min.js/wp-content/plugins/surplus-essentials/admin/js/v4-shims.min.jssurplus-essentials-admin?ver=jquery.timepicker.min?ver=chosen.jquery.min?ver=all.min?ver=v4-shims.min?ver=jquery-ui-fresh.min.css?ver=chosen.min.css?ver=HTML / DOM Fingerprints
ste-icons-wrap-templateste-icons-wrapste-icons-list<!--
This function is provided for demonstration purposes only.
An instance of this class should be passed to the run() function
defined in Surplus_Essentials_Loader as all of the hooks are defined
in that particular class.
The Surplus_Essentials_Loader will then create the relationship
between the defined hooks and the functions defined in this
class.
--><!--
* Add a form field in the new category page
*sociconsmsg