
Theme File Maker Security & Risk Analysis
wordpress.org/plugins/theme-file-makerThis plugin Lets you to create your own template pages
Is Theme File Maker Safe to Use in 2026?
Generally Safe
Score 85/100Theme File Maker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'theme-file-maker' v1.0.0 plugin presents a mixed security posture. On the positive side, it exhibits zero known CVEs, no critical or high severity taint flows, and its SQL queries are 100% prepared. The presence of a nonce check and capability check suggests some awareness of basic WordPress security principles. However, a significant concern lies in the complete lack of output escaping for all 18 identified outputs. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be injected into the output without proper sanitization, potentially leading to arbitrary code execution within the browser context of other users.
While the plugin boasts a small attack surface with no entry points exposed without authentication, the severe oversight in output escaping negates much of this strength. The absence of any recorded vulnerabilities in its history might be due to its simplicity or limited usage, but it does not inherently guarantee future security. The lack of critical taint flows or dangerous function usage is encouraging, but the identified unescaped outputs are a glaring weakness that requires immediate attention. A balanced conclusion suggests a plugin with some fundamental security awareness but a critical flaw in output handling that could be exploited.
Key Concerns
- 0% of outputs properly escaped
Theme File Maker Security Vulnerabilities
Theme File Maker Release Timeline
Theme File Maker Code Analysis
Output Escaping
Theme File Maker Attack Surface
WordPress Hooks 1
Maintenance & Trust
Theme File Maker Maintenance & Trust
Maintenance Signals
Community Trust
Theme File Maker Alternatives
Child Theme Creator by Orbisius
orbisius-child-theme-creator
Create Child Themes quickly and easily from any theme that you have currently installed on your site/blog.
Generate Child Theme
generate-child-theme
Create child themes of any WordPress themes effortlessly with Generate Child Theme.
Avantex Companion
avantex-companion
tested up to 6.8 License: GPLv3 or later License URI: http://www.gnu.org/licenses/gpl-3.0.html Avantex Companion is a companion plugin for Avantex the …
Marin Companion
marin-companion
Marin Companion is a companion plugin for Marin theme.
Envo Companion
envo-companion
Envo Companion is a companion plugin for Webenvo themes.
Theme File Maker Developer Profile
19 plugins · 9K total installs
How We Detect Theme File Maker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/theme-file-maker/style.csstheme-file-maker/style.css?ver=HTML / DOM Fingerprints
post-titlepost-title-linkclass