Thorium Extensions Security & Risk Analysis

wordpress.org/plugins/thorium-extension

Adds sections and new features to Thorium WordPress theme. 6 sections (Services, Portfolio, About Us, Team, Clients, Contact ) are included to make yo …

10 active installs v1.0.0 PHP + WP 4.5+ Updated Nov 7, 2017
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Thorium Extensions Safe to Use in 2026?

Generally Safe

Score 85/100

Thorium Extensions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of the "thorium-extension" plugin v1.0.0 reveals a generally strong security posture, with no identified dangerous functions, file operations, or external HTTP requests. The absence of any CVEs in its vulnerability history is also a positive indicator. However, there are significant areas for concern, primarily stemming from the complete lack of capability checks and nonce checks, coupled with a low percentage of properly escaped output. This suggests a potential for privilege escalation and Cross-Site Scripting (XSS) vulnerabilities, as the plugin does not implement standard WordPress security mechanisms to protect its entry points, even though the attack surface is currently reported as zero.

The vulnerability history, while clean, could also be interpreted cautiously. A lack of documented vulnerabilities might mean the plugin is new, not widely used, or has not been subjected to rigorous security testing. The low percentage of properly escaped output (48%) is a critical flag. While the attack surface is currently reported as zero, any future addition of AJAX handlers, REST API routes, or shortcodes without proper authentication and authorization checks, combined with unescaped output, would present a high risk.

In conclusion, the plugin demonstrates good practices by avoiding common pitfalls like dangerous functions and SQL injection through prepared statements. However, the absence of fundamental security checks like capability and nonce verifications, alongside a concerning rate of unescaped output, indicates a significant weakness that requires immediate attention. The clean vulnerability history is a positive, but the potential for exploitation due to the identified code signals should not be underestimated.

Key Concerns

  • Missing nonce checks on AJAX handlers (implied)
  • Missing capability checks on entry points (implied)
  • Low percentage of properly escaped output
  • SQL queries without prepared statements (67% prepared implies 33% raw)
Vulnerabilities
None known

Thorium Extensions Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Thorium Extensions Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
108
100 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

48% escaped208 total outputs
Attack Surface

Thorium Extensions Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 24
actionthorium_frontpage_sectionsfront-sections\general-template.php:50
actionthorium_frontpage_sectionsfront-sections\general-template.php:51
actionthorium_frontpage_sectionsfront-sections\general-template.php:52
actionthorium_frontpage_sectionsfront-sections\general-template.php:53
actionthorium_frontpage_sectionsfront-sections\general-template.php:54
actionthorium_frontpage_sectionsfront-sections\general-template.php:55
actioncustomize_registerinc\customize\customizer.php:68
actioncustomize_controls_print_stylesinc\customize\customizer.php:75
actioncustomize_controls_enqueue_scriptsinc\customize\customizer.php:83
actioncustomize_preview_initinc\customize\customizer.php:93
filterdynamic_sidebar_paramsinc\functions.php:60
actionwp_headinc\functions.php:92
actionadmin_enqueue_scriptsinc\functions.php:164
actioninitinc\functions.php:175
actionwidgets_initinc\general-widget.php:50
actionadmin_enqueue_scriptsinc\widgets\class-widget-about.php:10
actionwidgets_initinc\widgets\class-widget-about.php:175
actionadmin_enqueue_scriptsinc\widgets\class-widget-client.php:10
actionwidgets_initinc\widgets\class-widget-client.php:114
actionadmin_enqueue_scriptsinc\widgets\class-widget-project.php:10
actionwidgets_initinc\widgets\class-widget-project.php:200
actionwidgets_initinc\widgets\class-widget-services.php:754
actionadmin_enqueue_scriptsinc\widgets\class-widget-team.php:10
actionwidgets_initinc\widgets\class-widget-team.php:148
Maintenance & Trust

Thorium Extensions Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedNov 7, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Thorium Extensions Alternatives

No alternatives data available yet.

Developer Profile

Thorium Extensions Developer Profile

Marvin Kome

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Thorium Extensions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/thorium-extension/css/customizer.css/wp-content/plugins/thorium-extension/js/customizer-ext.js/wp-content/plugins/thorium-extension/js/customizer-ext-preview.js
Script Paths
/wp-content/plugins/thorium-extension/js/customizer-ext.js/wp-content/plugins/thorium-extension/js/customizer-ext-preview.js
Version Parameters
thorium-extension/css/customizer.css?ver=thorium-extension/js/customizer-ext.js?ver=thorium-extension/js/customizer-ext-preview.js?ver=

HTML / DOM Fingerprints

Data Attributes
class="timeline-inverted"
JS Globals
var thorium_ext_widget_num
FAQ

Frequently Asked Questions about Thorium Extensions