
Ten&Two XSLT Processor Security & Risk Analysis
wordpress.org/plugins/tenandtwo-xslt-processorTransform and display XML from local and remote sources using PHP's XSL extension.
Is Ten&Two XSLT Processor Safe to Use in 2026?
Generally Safe
Score 92/100Ten&Two XSLT Processor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tenandtwo-xslt-processor plugin v1.0.7 exhibits a generally good security posture, with no known vulnerabilities or critical code signals. The static analysis reveals strong practices in handling SQL queries, with all queries utilizing prepared statements, and a high percentage of output escaping. The absence of dangerous functions, external HTTP requests, and taint analysis findings further contribute to a positive security assessment. File operations are present but are not flagged as a concern in this analysis.
However, there are areas for improvement. The plugin lacks nonce checks and capability checks on its entry points. While the static analysis indicates no unprotected entry points, the absence of these common security mechanisms can leave the plugin susceptible to certain types of attacks, particularly if any future vulnerabilities are discovered that could be exploited through these vectors. The vulnerability history is clean, which is a strong positive indicator of developer diligence and the plugin's robustness to date.
In conclusion, tenandtwo-xslt-processor is currently a low-risk plugin due to its clean vulnerability history and sound code practices regarding SQL and output escaping. The primary weakness lies in the absence of nonce and capability checks, which represent a potential, albeit currently unrealized, risk. It is recommended that these checks be implemented to further harden the plugin's security.
Key Concerns
- No nonce checks
- Only 1 capability check for 5 entry points
Ten&Two XSLT Processor Security Vulnerabilities
Ten&Two XSLT Processor Code Analysis
SQL Query Safety
Output Escaping
Ten&Two XSLT Processor Attack Surface
Shortcodes 5
WordPress Hooks 13
Maintenance & Trust
Ten&Two XSLT Processor Maintenance & Trust
Maintenance Signals
Community Trust
Ten&Two XSLT Processor Alternatives
XML Documents
xml-documents
Support for managing XML documents as a custom post type and displaying them with XSLT stylesheets.
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
wp-all-export
Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets
wp-all-import
Easily import any file of any size into any plugin, post type, custom field, or taxonomy. Supports WooCommerce, ACF, images, galleries, users, real es …
WP All Import – Import Add-On for ACF
csv-xml-import-for-acf
Drag & drop to import any CSV, Excel, XML, or Google Sheets file into Advanced Custom Fields. Supports repeaters, flexible content, galleries, and …
WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress
wp-ultimate-csv-importer
Effortlessly import, export, and migrate your WordPress data with WP Ultimate CSV Importer. This all-in-one solution supports CSV, XML, and Excel file …
Ten&Two XSLT Processor Developer Profile
1 plugin · 10 total installs
How We Detect Ten&Two XSLT Processor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tenandtwo-xslt-processor/includes/css/admin-style.css/wp-content/plugins/tenandtwo-xslt-processor/includes/css/xslt-help.css/wp-content/plugins/tenandtwo-xslt-processor/includes/js/xslt-admin-scripts.jstenandtwo-xslt-processor/includes/css/admin-style.css?ver=tenandtwo-xslt-processor/includes/css/xslt-help.css?ver=tenandtwo-xslt-processor/includes/js/xslt-admin-scripts.js?ver=HTML / DOM Fingerprints
xslt-metaboxxslt-help-wrapxslt-help-column<!-- XSLT Processor - Admin Notice --><!-- XSLT Processor - Help Page --><!-- XSLT Processor - Settings Page --><!-- XSLT Processor - Settings Page: Options Form -->data-xslt-processor-targetdata-xslt-processor-actionwindow.xslt_processor_params[xslt_transform_xml][xslt_select_xml][xslt_select_csv]