Terra Themes Tools Security & Risk Analysis

wordpress.org/plugins/terra-themes-tools

Terra Themes Tools registers custom post types (like Projects, Employees and more) with custom fields for themes from Terra Themes.

200 active installs v1.5 PHP + WP 4.5+ Updated Mar 14, 2020
terra-themesterra-themes-toolsterrathemes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Terra Themes Tools Safe to Use in 2026?

Generally Safe

Score 85/100

Terra Themes Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'terra-themes-tools' plugin version 1.5 demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are significant strengths. The high percentage of properly escaped outputs and the presence of nonce and capability checks further bolster its security. The lack of any recorded vulnerabilities or CVEs in its history is also a very positive indicator.

However, there is a single shortcode identified as an entry point. While the analysis indicates no unprotected entry points, shortcodes can sometimes be overlooked in security reviews, especially if they process user-supplied data without sufficient sanitization or validation. The taint analysis did not reveal any unsanitized paths, which is encouraging, but the presence of only 6 total flows analyzed might suggest a limited scope of testing or complexity within the plugin.

Overall, the plugin appears to be developed with security in mind, adhering to many best practices. The primary area for vigilance would be the shortcode functionality to ensure it handles any potential user input securely. The clean vulnerability history suggests a well-maintained and secure codebase.

Key Concerns

  • 1 shortcode identified as an entry point
Vulnerabilities
None known

Terra Themes Tools Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Terra Themes Tools Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
135 escaped
Nonce Checks
6
Capability Checks
12
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped142 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
<clients-metabox> (inc\metaboxes\clients-metabox.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Terra Themes Tools Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[terra-themes-header-slider] inc\slider\terra-themes-slider.php:206
WordPress Hooks 43
actionslides-category_edit_form_fieldsinc\custom-taxanomy-field\register-taxanomy-fields.php:17
actionedited_slides-categoryinc\custom-taxanomy-field\register-taxanomy-fields.php:18
filtermanage_edit-slides-category_columnsinc\custom-taxanomy-field\register-taxanomy-fields.php:54
filtermanage_slides-category_custom_columninc\custom-taxanomy-field\register-taxanomy-fields.php:69
actionload-post.phpinc\metaboxes\clients-metabox.php:18
actionload-post-new.phpinc\metaboxes\clients-metabox.php:19
actionadd_meta_boxesinc\metaboxes\clients-metabox.php:25
actionsave_postinc\metaboxes\clients-metabox.php:26
actionload-post.phpinc\metaboxes\employees-metabox.php:18
actionload-post-new.phpinc\metaboxes\employees-metabox.php:19
actionadd_meta_boxesinc\metaboxes\employees-metabox.php:25
actionsave_postinc\metaboxes\employees-metabox.php:26
actionload-post.phpinc\metaboxes\projects-metabox.php:17
actionload-post-new.phpinc\metaboxes\projects-metabox.php:18
actionadd_meta_boxesinc\metaboxes\projects-metabox.php:24
actionsave_postinc\metaboxes\projects-metabox.php:25
actionload-post.phpinc\metaboxes\slides-metabox.php:18
actionload-post-new.phpinc\metaboxes\slides-metabox.php:19
actionadd_meta_boxesinc\metaboxes\slides-metabox.php:25
actionsave_postinc\metaboxes\slides-metabox.php:26
actionload-post.phpinc\metaboxes\slides-shortcode-metabox.php:18
actionload-post-new.phpinc\metaboxes\slides-shortcode-metabox.php:19
actionadd_meta_boxesinc\metaboxes\slides-shortcode-metabox.php:25
actionsave_postinc\metaboxes\slides-shortcode-metabox.php:26
actionload-post.phpinc\metaboxes\testimonials-metabox.php:18
actionload-post-new.phpinc\metaboxes\testimonials-metabox.php:19
actionadd_meta_boxesinc\metaboxes\testimonials-metabox.php:25
actionsave_postinc\metaboxes\testimonials-metabox.php:26
actioninitinc\post-type-clients.php:69
actioninitinc\post-type-clients.php:107
actioninitinc\post-type-employees.php:69
actioninitinc\post-type-employees.php:107
actioninitinc\post-type-projects.php:69
actioninitinc\post-type-projects.php:107
actioninitinc\post-type-slides.php:69
actioninitinc\post-type-slides.php:107
actioninitinc\post-type-testimonials.php:68
actioninitinc\post-type-testimonials.php:107
actionplugins_loadedterra-themes-tools.php:37
actionplugins_loadedterra-themes-tools.php:38
actionadmin_enqueue_scriptsterra-themes-tools.php:39
actionafter_setup_themeterra-themes-tools.php:40
actionplugins_loadedterra-themes-tools.php:119
Maintenance & Trust

Terra Themes Tools Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedMar 14, 2020
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Alternatives

Terra Themes Tools Alternatives

No alternatives data available yet.

Developer Profile

Terra Themes Tools Developer Profile

terrathemes

2 plugins · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Terra Themes Tools

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/terra-themes-tools/inc/metaboxes/assets/terra-themes-metabox-style.css/wp-content/plugins/terra-themes-tools/inc/metaboxes/assets/terra-themes-metabox-scripts.js

HTML / DOM Fingerprints

CSS Classes
terra-themes-header-sliderowl-carouselheader-container
Data Attributes
data-autoplay
Shortcode Output
[terra-themes-header-slider
FAQ

Frequently Asked Questions about Terra Themes Tools