
Template Dictionary Security & Risk Analysis
wordpress.org/plugins/template-dictionaryA plugin for developers which provides template variables dictionary editable in backend.
Is Template Dictionary Safe to Use in 2026?
Generally Safe
Score 85/100Template Dictionary has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "template-dictionary" plugin v1.6.1 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of known CVEs, critical taint flows, and any history of vulnerabilities is a strong indicator of well-maintained and secure code. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for the vast majority of its SQL queries and incorporating nonce and capability checks for its entry points.
However, there are areas of concern that warrant attention. The taint analysis reveals 5 flows with unsanitized paths, all of which are flagged as high severity. This suggests a potential for attackers to inject malicious data that is not properly handled. Additionally, a significant weakness is the low percentage of properly escaped outputs (11%). This opens the door to Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the user's browser. The presence of file operations also requires careful scrutiny to ensure proper access controls and sanitization are in place.
In conclusion, while the plugin benefits from a clean vulnerability history and good security hygiene in SQL queries and authentication checks, the high number of unsanitized paths and the critically low rate of output escaping present a tangible risk. Addressing these specific code-level issues should be the priority for improving the plugin's overall security.
Key Concerns
- High severity taint flows with unsanitized paths
- Low percentage of properly escaped outputs
- Presence of file operations
Template Dictionary Security Vulnerabilities
Template Dictionary Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Template Dictionary Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
Template Dictionary Maintenance & Trust
Maintenance Signals
Community Trust
Template Dictionary Alternatives
Custom Global Variables
custom-global-variables
Easily create custom variables that can be accessed globally in Wordpress and PHP. Retrieval of information is extremely fast, with no database calls.
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
CMB2
cmb2
CMB2 is a metabox, custom fields, and forms library for WordPress that will blow your mind.
OptionTree
option-tree
Theme Options UI Builder for WordPress. A simple way to create & save Theme Options and Meta Boxes for free or premium themes.
Catch Themes Demo Import
catch-themes-demo-import
Catch Themes Demo Import is a simple and easy-to-use demo importer WordPress plugin that allows you to import the theme demo data Based on One Click D …
Template Dictionary Developer Profile
1 plugin · 10 total installs
How We Detect Template Dictionary
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/template-dictionary/admin/css/style.css/wp-content/plugins/template-dictionary/admin/js/script.js/wp-content/plugins/template-dictionary/includes/polylang.php/wp-content/plugins/template-dictionary/admin/admin.php/wp-content/plugins/template-dictionary/admin/js/script.jstemplate-dictionary/admin/css/style.css?ver=template-dictionary/admin/js/script.js?ver=HTML / DOM Fingerprints
tdict-admintdict-admin-listtdict-admin-formdata-tdict-codetemplate_dictionarytdict[tmpl_dict code=