Unicon extensions Security & Risk Analysis
wordpress.org/plugins/unicon-extensionssupport for special content types in your website, such as a service Block, client, and team member.
Is Unicon extensions Safe to Use in 2026?
Generally Safe
Score 85/100Unicon extensions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "unicon-extensions" v1.0.5 plugin reveals a generally positive security posture. The plugin exhibits a clean attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no unprotected entry points were identified. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design.
However, a significant concern arises from the presence of a single SQL query that does not utilize prepared statements. This could potentially expose the plugin to SQL injection vulnerabilities if the data used in the query is not rigorously sanitized. Additionally, a low percentage (29%) of proper output escaping is a considerable weakness, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks on any entry points, coupled with only one capability check present, indicates a potential reliance on other security mechanisms or a simplified security model that may not be robust enough in all scenarios.
Furthermore, the plugin has no recorded vulnerability history, which is a strong positive indicator. This suggests either diligent development practices, a lack of past exploitable flaws, or potentially that the plugin has not been extensively targeted or analyzed. Despite the strengths in attack surface management and lack of historical vulnerabilities, the identified raw SQL query and significant output escaping issues warrant attention to mitigate potential security risks.
Key Concerns
- SQL query without prepared statements
- Low percentage of properly escaped output
- No nonce checks found
Unicon extensions Security Vulnerabilities
Unicon extensions Code Analysis
SQL Query Safety
Output Escaping
Unicon extensions Attack Surface
WordPress Hooks 3
Maintenance & Trust
Unicon extensions Maintenance & Trust
Maintenance Signals
Community Trust
Unicon extensions Alternatives
Promote extensions
promote-extensions
support for special content types in your website, such as a service Block, client, and team member,counter.
Aazeen extension
aazeen-extension
support for special content types in your website, such as a service Block, client, and team member.
Azeen Core
azeen-core
support for special content types in your website, such as a service Block, client, and team member.
Dashboard Widgets Control
dashboard-widgets-control
Displays all registered dashboard widgets and enables to remove them individually for all or for selected roles (clients or other site contributors).
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
Unicon extensions Developer Profile
3 plugins · 140 total installs
How We Detect Unicon extensions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/unicon-extensions/assets/js/unicon_widgets_custom_css.css/wp-content/plugins/unicon-extensions/assets/js/widget-media.jsunicon-extensions/assets/js/unicon_widgets_custom_css.css?ver=unicon-extensions/assets/js/widget-media.js?ver=