
Thesis Footer Tool Security & Risk Analysis
wordpress.org/plugins/thesis-footer-toolProvides a simple way to manage items in and around the footer of a Thesis Theme.
Is Thesis Footer Tool Safe to Use in 2026?
Generally Safe
Score 85/100Thesis Footer Tool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "thesis-footer-tool" v0.1 plugin exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) and the static analysis shows a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events. Additionally, all SQL queries utilize prepared statements, which is a strong security practice. However, there are significant concerns, primarily stemming from the lack of output escaping. With 100% of outputs unescaped, this plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Any data processed or displayed by the plugin, if not properly sanitized before rendering, could be exploited by attackers to inject malicious scripts.
The absence of taint analysis flows doesn't necessarily mean there are no vulnerabilities, but rather that the analysis might not have found them based on its defined rules or the code structure. The lack of capability checks and nonce checks on what would typically be entry points (if any existed) also raises concerns, though the current analysis reports zero such entry points. The vulnerability history being clean is a positive indicator, but it cannot compensate for the critical flaw of unescaped output, which is a fundamental security requirement for any WordPress plugin. The plugin's strengths lie in its minimal attack surface and secure SQL practices, but its weakness in output sanitization poses a severe risk.
Key Concerns
- No output escaping
- No capability checks
- No nonce checks
Thesis Footer Tool Security Vulnerabilities
Thesis Footer Tool Code Analysis
Output Escaping
Thesis Footer Tool Attack Surface
WordPress Hooks 8
Maintenance & Trust
Thesis Footer Tool Maintenance & Trust
Maintenance Signals
Community Trust
Thesis Footer Tool Alternatives
Fast Post Lists
fast-post-lists
Provide shortcodes to display a filtered list of posts, grouped by category/tag, with optional thumbnails.
Index Press
index-press
Provides a standard index of content in your site using a short code. Sorts results into alphabetical listings.
Post Theming
post-theming
Allows you to change how posts will appear in lists on your web site.
Table of Contents Plus
table-of-contents-plus
A powerful yet user friendly plugin that automatically creates a table of contents. Can also output a sitemap listing all pages and categories.
Rich Table of Contents
rich-table-of-content
RTOC is a table of contents generation plugin from Japan that allows anyone to easily create a table of contents. Equipped with the functions of the c …
Thesis Footer Tool Developer Profile
7 plugins · 170 total installs
How We Detect Thesis Footer Tool
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/thesis-footer-tool/thesis-footer-tool.css/wp-content/plugins/thesis-footer-tool/thesis-footer-tool.js/wp-content/plugins/thesis-footer-tool/thesis-footer-tool.jsHTML / DOM Fingerprints
rp-contributorrp_contributor_notes