Thememiles Toolset Security & Risk Analysis

wordpress.org/plugins/thememiles-toolset

Import ThemeMiles Official Themes Demo Content, Widgets and Theme settings with just one click.

600 active installs v1.1.2 PHP 7.0.0+ WP 5.0+ Updated Jun 11, 2023
demoimporterone-click-importtheme-demosthememiles
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Thememiles Toolset Safe to Use in 2026?

Generally Safe

Score 85/100

Thememiles Toolset has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin 'thememiles-toolset' v1.1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests, along with 100% output escaping and the use of prepared statements for all SQL queries, are excellent security practices. The plugin also demonstrates awareness of security mechanisms with the presence of nonce and capability checks.

However, a significant concern arises from the presence of a single AJAX handler that lacks authentication checks. This constitutes an unprotected entry point into the plugin's functionality, creating a potential attack vector. While the taint analysis did not reveal any immediate critical or high severity issues, the unprotected AJAX handler could be exploited to trigger unintended actions or reveal sensitive information if not properly secured within its logic.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator, suggesting that the developers have either maintained a secure codebase or have been diligent in patching past issues. Nonetheless, the presence of an unprotected entry point in this version is a critical flaw that requires immediate attention, irrespective of past security records. The overall assessment is good, but this single unprotected entry point significantly lowers the security confidence.

Key Concerns

  • Unprotected AJAX handler found
Vulnerabilities
None known

Thememiles Toolset Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Thememiles Toolset Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface
1 unprotected

Thememiles Toolset Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_thememiles_toolset_getting_startedinc\init.php:46
WordPress Hooks 6
filteradvanced_import_demo_listsinc\init.php:44
filteradmin_menuinc\init.php:45
filteradmin_enqueue_scriptsinc\init.php:47
filteradmin_enqueue_scriptsinc\init.php:48
actionadvanced_import_replace_term_idsinc\init.php:51
actionadvanced_import_replace_post_idsinc\init.php:52
Maintenance & Trust

Thememiles Toolset Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 11, 2023
PHP min version7.0.0
Downloads30K

Community Trust

Rating100/100
Number of ratings1
Active installs600
Developer Profile

Thememiles Toolset Developer Profile

thememiles

2 plugins · 800 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Thememiles Toolset

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/thememiles-toolset/assets/thememiles-toolset.css/wp-content/plugins/thememiles-toolset/assets/thememiles-toolset.js
Script Paths
/wp-content/plugins/thememiles-toolset/assets/thememiles-toolset.js
Version Parameters
thememiles-toolset/assets/thememiles-toolset.css?ver=thememiles-toolset/assets/thememiles-toolset.js?ver=

HTML / DOM Fingerprints

CSS Classes
ads-containerads-screenshotads-noticeplugin-install-noticeads-gsm-btnbutton-primarybutton-hero
Data Attributes
data-namedata-slugaria-label
JS Globals
thememiles_toolset
FAQ

Frequently Asked Questions about Thememiles Toolset