
Theme Folders Security & Risk Analysis
wordpress.org/plugins/theme-foldersA plugin to sort themes. For an easy overview about your favorite Themes.
Is Theme Folders Safe to Use in 2026?
Generally Safe
Score 85/100Theme Folders has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "theme-folders" v0.2 plugin presents a mixed security posture. On one hand, it boasts a clean vulnerability history with no known CVEs, indicating a potentially stable and well-maintained codebase. The static analysis also shows no dangerous functions, no direct SQL queries without prepared statements, and no file operations or external HTTP requests, which are positive indicators. However, there are significant concerns within the code analysis. A critical weakness is that 100% of the 10 identified output operations are not properly escaped. This means that any data output by the plugin could be vulnerable to cross-site scripting (XSS) attacks if that data originates from user input or external sources without prior sanitization.
The taint analysis reveals two flows with unsanitized paths. While these are not classified as critical or high severity, the presence of unsanitized paths suggests a potential for unexpected behavior or data manipulation if these flows are triggered in specific ways. The complete absence of nonce checks and capability checks on any entry points, although the attack surface is reported as zero, is a concern. If the attack surface were to expand in future versions or if the reporting is incomplete, these missing checks would be a significant vulnerability. Therefore, while the plugin appears to have a good track record and avoids common pitfalls like raw SQL, the lack of output escaping and the presence of unsanitized paths are notable risks that need to be addressed.
Key Concerns
- 100% of outputs are unescaped
- 2 flows with unsanitized paths
- 0 Nonce checks on entry points
- 0 Capability checks on entry points
Theme Folders Security Vulnerabilities
Theme Folders Code Analysis
Output Escaping
Data Flow Analysis
Theme Folders Attack Surface
WordPress Hooks 1
Maintenance & Trust
Theme Folders Maintenance & Trust
Maintenance Signals
Community Trust
Theme Folders Alternatives
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
Categories Images
categories-images
The Categories Images is a Wordpress plugin allow you to add image to category, tag or custom taxonomy.
Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI
simple-tags
Tags, Categories and WordPress terms are easy with TaxoPress. Add a Tag or Category to Pages, manage your WooCommerce Categories and Tags and more.
Ultimate Category Excluder
ultimate-category-excluder
Ultimate Category Excluder allows you to quickly and easily exclude categories from your front page, archives, feeds, and search results.
Category Posts Widget
category-posts
Adds a widget that shows the most recent posts from a single category.
Theme Folders Developer Profile
11 plugins · 220 total installs
How We Detect Theme Folders
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
theme_folder_itemno-linesid="theme_folder_item"id="theme-form-name="design_folders"