
Theme Grep by BoldGrid Security & Risk Analysis
wordpress.org/plugins/theme-grep-by-boldgridTheme Grep helps to review WordPress themes by automating many searches (greps) used to "snoop around" the theme's code.
Is Theme Grep by BoldGrid Safe to Use in 2026?
Generally Safe
Score 100/100Theme Grep by BoldGrid has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "theme-grep-by-boldgrid" v1.0.0 presents a mixed security posture. On the positive side, the static analysis indicates a clean attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. All detected SQL queries utilize prepared statements, and the vast majority of output is properly escaped, suggesting good practices in handling user-provided data and database interactions. The absence of any recorded vulnerabilities (CVEs) in its history is also a strong indicator of a well-maintained and secure codebase.
However, the presence of two instances of the `shell_exec` function raises a significant concern. While the static analysis does not reveal any specific taint flows originating from these functions in this version, their mere existence represents a potential entry point for command injection vulnerabilities if the input passed to them is not rigorously sanitized and validated. Furthermore, the complete lack of nonce and capability checks across the entire plugin, while seemingly mitigated by the zero attack surface, leaves a theoretical backdoor if any entry points were to be introduced in future updates without proper security considerations. Therefore, while the current version appears robust due to a limited attack surface and strong SQL/output handling, the `shell_exec` usage and absence of authorization checks warrant careful monitoring and potential remediation.
Key Concerns
- Dangerous function shell_exec found
- No nonce checks implemented
- No capability checks implemented
Theme Grep by BoldGrid Security Vulnerabilities
Theme Grep by BoldGrid Code Analysis
Dangerous Functions Found
Output Escaping
Theme Grep by BoldGrid Attack Surface
WordPress Hooks 4
Maintenance & Trust
Theme Grep by BoldGrid Maintenance & Trust
Maintenance Signals
Community Trust
Theme Grep by BoldGrid Alternatives
CampusPress Code Check
campuspress-theme-check
A simple and easy way to test your theme or plugin for all the latest WordPress standards and practices. A great theme development tool!
Color Changer
color-changer
Color Changer is there to help you out when you get bored of seeing the black & white colors of the editor. Click in the Color Changer Button and …
Eligibility Checklist for AdSense
eligibility-checklist-for-adsense
A full AdSense approval & policy audit dashboard for 2025. Scans your site using external keyword lists, content heuristics, and policy checks — w …
Backlink Checker SEO
backlink-checker-seo
Backlink Checker SEO tool shows an instant result of earned backlinks to your site.
Keyword Difficulty Tool
keyword-difficulty-tool
Be smart, competitive keywords are hard to rank, let's find an easier one.
Theme Grep by BoldGrid Developer Profile
15 plugins · 1.1M total installs
How We Detect Theme Grep by BoldGrid
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/theme-grep-by-boldgrid/css/boldgrid-theme-grep-admin.css/wp-content/plugins/theme-grep-by-boldgrid/js/boldgrid-theme-grep-admin.js/wp-content/plugins/theme-grep-by-boldgrid/js/jquery.sticky.js/wp-content/plugins/theme-grep-by-boldgrid/js/boldgrid-theme-grep-admin.js/wp-content/plugins/theme-grep-by-boldgrid/js/jquery.sticky.jsboldgrid-theme-grep-admin.css?ver=boldgrid-theme-grep-admin.js?ver=jquery.sticky.js?ver=HTML / DOM Fingerprints
Include this file with a build process.https://github.com/garand/stickybgthgr-sticky