
Theme Wing Security & Risk Analysis
wordpress.org/plugins/theme-wingTheme wing is an optional plugin for official Blazethemes theme. It adds additional functionality such as custom post types, custom post meta fields a …
Is Theme Wing Safe to Use in 2026?
Generally Safe
Score 100/100Theme Wing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "theme-wing" v1.0.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface, with zero identified unprotected entry points. The code signals further reinforce this positive assessment, showing no dangerous functions, all SQL queries utilizing prepared statements, and a low incidence of file operations or external HTTP requests. The presence of nonce and capability checks, though limited in number, indicates an awareness of basic security principles.
No critical or high-severity taint flows were detected, which is a significant positive indicator of secure coding practices regarding data handling. The vulnerability history is entirely clear, with no known CVEs, past or present. This lack of historical vulnerabilities, coupled with the clean static analysis, suggests that the plugin has either been developed with robust security in mind or has not yet been a target for exploitation. However, it's worth noting that 17% of output escaping is not properly handled, which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. Despite this minor concern, the overall security of the plugin appears to be very good.
Key Concerns
- Unescaped output detected
Theme Wing Security Vulnerabilities
Theme Wing Code Analysis
Output Escaping
Theme Wing Attack Surface
WordPress Hooks 13
Maintenance & Trust
Theme Wing Maintenance & Trust
Maintenance Signals
Community Trust
Theme Wing Alternatives
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
Sydney Toolbox
sydney-toolbox
Registers custom post types and custom fields for the Sydney theme
Custom Post Types and Custom Fields creator – WCK
wck-custom-fields-and-custom-post-types-creator
A must have tool for creating custom fields, custom post types and taxonomies, fast and without any programming knowledge.
CubeWP Framework
cubewp-framework
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
Theme Wing Developer Profile
25 plugins · 36K total installs
How We Detect Theme Wing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/theme-wing/assets/lib/fontawesome/css/all.min.css/wp-content/plugins/theme-wing/admin/metaboxes/metaboxes.css/wp-content/plugins/theme-wing/admin/metaboxes/metaboxes.js/wp-content/plugins/theme-wing/admin/metaboxes/metaboxes.jstheme-wing/assets/lib/fontawesome/css/all.min.css?ver=theme-wing/admin/metaboxes/metaboxes.css?ver=theme-wing/admin/metaboxes/metaboxes.js?ver=HTML / DOM Fingerprints
Plugin Name: Theme WingDescription: Adds up functionali ty like custom post types and custom post meta for blazethemes themes.Author: Blaze ThemesAuthor URI: https://blazethemes.com/+11 moredata-theme-wing-versiontheme_wing_metaboxes_params/wp-json/theme-wing/v1/services/wp-json/theme-wing/v1/team/wp-json/theme-wing/v1/pricing/wp-json/theme-wing/v1/projects[theme_wing_services][theme_wing_team][theme_wing_pricing][theme_wing_projects]