
Ultra Companion – Companion plugin for WPoperation Themes Security & Risk Analysis
wordpress.org/plugins/ultra-companionThis is the companion plugin for WPoperation themes. This plugin will add extra features to the theme theme by adding social share, shortcodes, post v …
Is Ultra Companion – Companion plugin for WPoperation Themes Safe to Use in 2026?
Generally Safe
Score 92/100Ultra Companion – Companion plugin for WPoperation Themes has a strong security track record. Known vulnerabilities have been patched promptly.
The "ultra-companion" plugin version 1.2.0 presents a mixed security posture. On the positive side, the code exhibits good practices with 100% of SQL queries using prepared statements and a high rate of output escaping (92%). It also demonstrates a reasonable number of nonce and capability checks, with no critical or high-severity taint flows identified. However, a significant concern arises from the attack surface, which includes two AJAX handlers, with one entirely lacking authentication checks. This single unprotected entry point is a critical vulnerability that could be exploited to execute unauthorized actions.
The plugin's vulnerability history, while currently showing no unpatched vulnerabilities, does reveal a past medium-severity Cross-Site Scripting (XSS) issue, last recorded in early 2024. This indicates a historical propensity for input sanitization weaknesses, even though the current static analysis didn't flag direct XSS issues. The absence of unpatched CVEs is a strong positive, but the presence of an unprotected AJAX handler combined with the past XSS vulnerability suggests that careful review and hardening of all entry points are crucial.
In conclusion, while the plugin has strengths in its handling of SQL and output escaping, the unprotected AJAX handler represents a direct and exploitable security risk. The historical XSS vulnerability, though patched, warrants continued vigilance regarding input validation. A balanced assessment suggests that the plugin is moderately secure but requires immediate attention to its unprotected entry point to mitigate potential exploitation.
Key Concerns
- Unprotected AJAX handler
- Past medium severity CVE (XSS)
Ultra Companion – Companion plugin for WPoperation Themes Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Ultra Companion <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Ultra Companion – Companion plugin for WPoperation Themes Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Ultra Companion – Companion plugin for WPoperation Themes Attack Surface
AJAX Handlers 2
WordPress Hooks 35
Maintenance & Trust
Ultra Companion – Companion plugin for WPoperation Themes Maintenance & Trust
Maintenance Signals
Community Trust
Ultra Companion – Companion plugin for WPoperation Themes Alternatives
Publishers
publishers
Companion plugin for the Publishers theme: https://wordpress.org/themes/publishers/.
Shapely Companion
shapely-companion
Shapely Companion is a companion plugin for Shapely WordPress theme by Colorlib.com.
Blesk Companion
blesk-companion
Blesk Companion is a companion plugin for Blesk WordPress theme by Colorlib.com.
Mosh Companion
mosh-companion
Mosh Companion is a companion plugin for Companion WordPress theme by Colorlib.com.
Fashe Companion
fashe-companion
Fashe Companion is a companion plugin for Fashe WordPress theme by Colorlib.com.
Ultra Companion – Companion plugin for WPoperation Themes Developer Profile
9 plugins · 17K total installs
How We Detect Ultra Companion – Companion plugin for WPoperation Themes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ultra-companion/assets/slick/slick.css/wp-content/plugins/ultra-companion/assets/slick/slick-theme.css/wp-content/plugins/ultra-companion/assets/js/media-uploader.js/wp-content/plugins/ultra-companion/assets/js/admin.js/wp-content/plugins/ultra-companion/assets/css/admin.css/wp-content/plugins/ultra-companion/assets/slick/slick.jsultra-companion/assets/slick/slick.js?ver=1.2.0HTML / DOM Fingerprints
wpop_admin_noticewpop_notice_imgwpop_notice_right_contentwpop_notice_contentwpop_no_thankswpop_notice_after_contentwpop_notice_content_wrapwpop_buttondata-userULC_VERSIONULC_TDULC_PATHULC_URLUIMAGE_PATH