
What Template Am I Using Security & Risk Analysis
wordpress.org/plugins/what-template-am-i-usingThis plugin is intended for theme developers to use. It shows the current template being used to render the page, current post type, and much more.
Is What Template Am I Using Safe to Use in 2026?
Generally Safe
Score 85/100What Template Am I Using has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'what-template-am-i-using' plugin version 0.2.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and has no recorded vulnerability history, suggesting a generally well-maintained codebase. The absence of dangerous functions and file operations is also reassuring.
However, there are significant concerns related to its attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This means that any user, including unauthenticated ones, could potentially trigger these handlers. While the taint analysis showed only one flow with an unsanitized path and no critical or high severity issues, the lack of proper output escaping on a significant portion of its outputs (71%) is a notable weakness. This, combined with the unprotected AJAX endpoints, could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled securely within these handlers.
The plugin's strengths lie in its SQL handling and lack of past vulnerabilities. Its weaknesses are concentrated in its entry points and output sanitization. The absence of direct vulnerabilities in its history is positive, but the current code analysis reveals areas that require immediate attention to prevent potential exploitation.
Key Concerns
- AJAX handlers without authentication checks
- Unescaped output on 71% of outputs
- Lack of nonce checks on AJAX handlers
- Flow with unsanitized path
What Template Am I Using Security Vulnerabilities
What Template Am I Using Code Analysis
Output Escaping
Data Flow Analysis
What Template Am I Using Attack Surface
AJAX Handlers 2
WordPress Hooks 15
Maintenance & Trust
What Template Am I Using Maintenance & Trust
Maintenance Signals
Community Trust
What Template Am I Using Alternatives
which template file
which-template-file
Show the name of the php file of your theme used to display the current page.
Monster Widget
monster-widget
Provides a quick and easy method of adding all core widgets to a sidebar for testing purposes.
What Template
what-template
Adds the current page's template name to the admin bar.
Category Template Hierarchy
category-template-hierarchy
Adds parent-category.php, child-category.php, and child-category-{slug|id} templates to the hierarchy and conditional tags to match.
Block Widgets Monster
block-widgets-monster
Quick and easy testing of multiple WordPress and/or WooCommerce block/legacy widgets. Not intended for production use.
What Template Am I Using Developer Profile
4 plugins · 330 total installs
How We Detect What Template Am I Using
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/what-template-am-i-using/assets/css/main.css/wp-content/plugins/what-template-am-i-using/assets/js/main.js/wp-content/plugins/what-template-am-i-using/assets/js/main.jswhat-template-am-i-using/assets/css/main.css?ver=what-template-am-i-using/assets/js/main.js?ver=HTML / DOM Fingerprints
wtaiu-sidebarwtaiu-togglewtaiu-contentwtaiu-panelwtaiu-panel-headerwtaiu-panel-contentwtaiu-sidebar-handle<!-- WTAIU: BEGIN SIDEBAR --><!-- WTAIU: END SIDEBAR -->data-wtaiu-sidebardata-wtaiu-toggle-sidebardata-wtaiu-save-urlwtaiu/wp-json/wtaiu/v1/panels