Theme Blvd Widget Pack Security & Risk Analysis

wordpress.org/plugins/theme-blvd-widget-pack

When using a Theme Blvd theme, this plugin adds a few widgets to extend some of the functionality already built into the framework.

2K active installs v1.0.6 PHP + WP + Updated Apr 4, 2018
jason-bobichtheme-blvdthemeblvdwidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Theme Blvd Widget Pack Safe to Use in 2026?

Generally Safe

Score 85/100

Theme Blvd Widget Pack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The theme-blvd-widget-pack plugin, in version 1.0.6, exhibits a generally strong security posture based on the static analysis. The absence of any reported vulnerabilities in its history is a significant positive indicator, suggesting a commitment to security or a lack of publicly disclosed issues. The code analysis reveals a promising lack of dangerous functions, raw SQL queries, file operations, and external HTTP requests. The presence of a nonce check is also a good practice. However, a notable concern arises from the output escaping, where only 25% of outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being rendered in the browser. While taint analysis showed no unsanitized flows, the low output escaping percentage means this could be a latent risk.

Despite the positive indicators like no known CVEs and a clean taint analysis, the low percentage of properly escaped output presents a clear weakness. This suggests a medium-level risk for XSS vulnerabilities that could be exploited, especially if the plugin handles user-generated content in its widgets. The plugin's strengths lie in its secure handling of database operations and its minimal attack surface from entry points. The weakness is specifically tied to output sanitization, which requires careful attention. In conclusion, while the plugin appears to have a good track record and secure core functionalities, the insufficient output escaping is a significant area of concern that needs to be addressed to mitigate potential XSS risks.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Theme Blvd Widget Pack Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Theme Blvd Widget Pack Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
135
46 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped181 total outputs
Attack Surface

Theme Blvd Widget Pack Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterterms_clausesincludes\tb-widget-mini-post-grid.php:92
filterterms_clausesincludes\tb-widget-mini-post-list.php:90
actionadmin_noticestb-widget-pack.php:44
actionadmin_inittb-widget-pack.php:46
actionafter_setup_themetb-widget-pack.php:69
actioninittb-widget-pack.php:81
Maintenance & Trust

Theme Blvd Widget Pack Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 4, 2018
PHP min version
Downloads61K

Community Trust

Rating0/100
Number of ratings0
Active installs2K
Developer Profile

Theme Blvd Widget Pack Developer Profile

Jason

22 plugins · 8K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
3363 days
View full developer profile
Detection Fingerprints

How We Detect Theme Blvd Widget Pack

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/theme-blvd-widget-pack/includes/general.php/wp-content/plugins/theme-blvd-widget-pack/includes/tb-widget-contact.php/wp-content/plugins/theme-blvd-widget-pack/includes/tb-widget-horz-nav.php/wp-content/plugins/theme-blvd-widget-pack/includes/tb-widget-mini-post-grid.php/wp-content/plugins/theme-blvd-widget-pack/includes/tb-widget-mini-post-list.php
Version Parameters
theme-blvd-widget-pack/includes/general.php?ver=theme-blvd-widget-pack/includes/tb-widget-contact.php?ver=theme-blvd-widget-pack/includes/tb-widget-horz-nav.php?ver=theme-blvd-widget-pack/includes/tb-widget-mini-post-grid.php?ver=theme-blvd-widget-pack/includes/tb-widget-mini-post-list.php?ver=

HTML / DOM Fingerprints

CSS Classes
tb-mini_post_list_widget
Data Attributes
id="themeblvd_mini_post_list_widget"name="themeblvd_mini_post_list_widget"
FAQ

Frequently Asked Questions about Theme Blvd Widget Pack