
ThemeFarmer Companion Security & Risk Analysis
wordpress.org/plugins/themefarmer-companionAdvance Extension For ThemeFarmer Theme. enjoy full functionality of ThemeFarmer theme by installing this plugin.
Is ThemeFarmer Companion Safe to Use in 2026?
Generally Safe
Score 85/100ThemeFarmer Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The themefarmer-companion plugin v1.3.6 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history are significant strengths, suggesting a proactive approach to security by the developers or a history of diligent patching. The code analysis reveals a well-defined attack surface with all identified entry points (AJAX handlers) protected by nonce checks. Furthermore, the plugin demonstrates good practices in handling SQL queries with 100% prepared statements and a high percentage of properly escaped output, mitigating common web application vulnerabilities. The limited number of file operations and lack of external HTTP requests further reduce potential attack vectors.
However, a critical weakness identified is the complete absence of capability checks for its AJAX handlers. While nonce checks prevent unauthorized requests, they do not prevent authenticated users from performing actions they shouldn't be able to. This could lead to privilege escalation or unauthorized actions if the AJAX handlers perform sensitive operations. The static analysis did not identify any taint flows, which is positive, but the limited scope of taint analysis in this report (0 flows analyzed) means this should not be considered a definitive indicator of complete safety. The bundled Select2 library, while not flagged as outdated, represents a potential area of concern if it is an older version that may contain known vulnerabilities.
Key Concerns
- AJAX handlers lack capability checks
- Bundled library (Select2) potential version concern
ThemeFarmer Companion Security Vulnerabilities
ThemeFarmer Companion Release Timeline
ThemeFarmer Companion Code Analysis
Bundled Libraries
Output Escaping
ThemeFarmer Companion Attack Surface
AJAX Handlers 2
WordPress Hooks 34
Maintenance & Trust
ThemeFarmer Companion Maintenance & Trust
Maintenance Signals
Community Trust
ThemeFarmer Companion Alternatives
Walker Core
walker-core
Walker Core is the companion plugin for WalkerWP Themes, which provides core functionality and custom post type for the themes.
Ultimate Carousel
ultimate-carousel
Ultimate Corusel is very simple and free to create slider in your WordPress website. You can add pictures in (PNG, JPG and GIF Even Video) posts, pag …
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials
testimonial-free
A Customizable Testimonial plugin to Automate Collecting, Filtering, and Publishing Customer Reviews. Testimonial Slider, Grid & More to Grow Sales
Testimonial – Testimonial Slider and Showcase Plugin
testimonial-slider-and-showcase
Display customer testimonials beautifully with responsive slider and grid layouts. Build trust and boost conversions with this WordPress testimonial p …
ThemeFarmer Companion Developer Profile
3 plugins · 3K total installs
How We Detect ThemeFarmer Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/themefarmer-companion/assets/js/themefarmer-front.js/wp-content/plugins/themefarmer-companion/inc/functions.php/wp-content/plugins/themefarmer-companion/inc/sanitize-cb.php/wp-content/plugins/themefarmer-companion/inc/home-sections.php/wp-content/plugins/themefarmer-companion/inc/companion-customizer.php/wp-content/plugins/themefarmer-companion/inc/class-themefarmer-menu-icon-walker.php/wp-content/plugins/themefarmer-companion/fields/fields-init.php/wp-content/plugins/themefarmer-companion/theme-files/newstore-functions.php+11 more/wp-content/plugins/themefarmer-companion/assets/js/themefarmer-front.js/assets/js/themefarmer-front.js?ver=/inc/functions.php?ver=/inc/sanitize-cb.php?ver=/inc/home-sections.php?ver=/inc/companion-customizer.php?ver=/inc/class-themefarmer-menu-icon-walker.php?ver=/fields/fields-init.php?ver=/theme-files/newstore-functions.php?ver=/theme-files/storez-functions.php?ver=/inc/class-themefarmer-wc-widget-products.php?ver=/theme-files/scope-customizer.php?ver=/theme-files/amazica-customizer.php?ver=HTML / DOM Fingerprints
themefarmer_companion_obj