Tally Theme Setup Security & Risk Analysis

wordpress.org/plugins/tally-theme-setup

Import demo content for Tally Themes

100 active installs v2.2 PHP + WP 4.4+ Updated Aug 10, 2017
importersample-datasample-data-importertallythemes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tally Theme Setup Safe to Use in 2026?

Generally Safe

Score 85/100

Tally Theme Setup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The Tally Theme Setup plugin version 2.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerabilities or CVEs. The absence of external HTTP requests and bundled libraries is also a strength. However, significant concerns arise from the attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This is a critical security oversight that could allow unauthenticated users to trigger potentially harmful actions. While taint analysis did not reveal any immediate issues, the unprotected AJAX endpoints create a significant risk of exploitation if any functionality within them is sensitive or can be manipulated by user input.

Key Concerns

  • AJAX handlers without authentication checks
  • Limited output escaping (only 61% proper)
Vulnerabilities
None known

Tally Theme Setup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tally Theme Setup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
65
100 escaped
Nonce Checks
4
Capability Checks
0
File Operations
19
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

61% escaped165 total outputs
Attack Surface
2 unprotected

Tally Theme Setup Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_tallythemesetup_demo_importloader-v1.php:35
authwp_ajax_tallythemesetup_demo_importloader-v2.php:44
WordPress Hooks 12
filterimport_post_meta_keyinc\import-xml-old.php:93
filterhttp_request_timeoutinc\import-xml-old.php:94
filterimport_post_meta_keyinc\import-xml.php:100
filterhttp_request_timeoutinc\import-xml.php:101
actionadmin_noticesinc\notice.php:2
actionadmin_initinc\notice.php:86
actionadmin_enqueue_scriptsinc\script-loader.php:8
actionadmin_menuloader-v1.php:255
actionadmin_enqueue_scriptsloader-v2.php:45
actionadmin_noticesloader-v2.php:46
actionadmin_menuloader-v2.php:47
actionafter_setup_themetally-theme-setup.php:43
Maintenance & Trust

Tally Theme Setup Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedAug 10, 2017
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Tally Theme Setup Developer Profile

TallyThemes

5 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tally Theme Setup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tally-theme-setup/assets/css/admin.css/wp-content/plugins/tally-theme-setup/assets/js/bootstrapguru-import.js
Script Paths
/wp-content/plugins/tally-theme-setup/assets/js/bootstrapguru-import.js
Version Parameters
tally-theme-setup/assets/css/admin.css?ver=tally-theme-setup/assets/js/bootstrapguru-import.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!--Sample contents are imported.--><!--XML Import Fail--><!--Class: <strong>tallythemesetup_import</strong> not found--><!--Widgets are imported.-->+3 more
Data Attributes
data-slugdata-action
JS Globals
tallythemesetup_importtallythemesetup_process_widget_data
FAQ

Frequently Asked Questions about Tally Theme Setup