
Wing Suite Security & Risk Analysis
wordpress.org/plugins/wing-suiteYour all-in-one WordPress enhancement suite — starting with Dark Mode and AJAX Search modules. More modules coming soon.
Is Wing Suite Safe to Use in 2026?
Generally Safe
Score 100/100Wing Suite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wing-suite" v1.0.0 plugin exhibits a generally positive security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are strong indicators of secure coding practices. The presence of a nonce check is also a positive sign for handling AJAX requests, though the lack of capability checks on the AJAX handlers is a notable concern.
The main area of concern arises from the output escaping. With 53% of outputs not properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis did not reveal any specific issues, the high percentage of unescaped output presents a latent threat that could be exploited if malicious data is introduced into these output flows.
The plugin has no recorded vulnerability history, which is excellent. This suggests a good track record and potentially a diligent development process. However, the absence of past vulnerabilities does not negate the risks identified in the static analysis, particularly concerning the unescaped output. The overall conclusion is that "wing-suite" v1.0.0 has a solid foundation with no critical code-level vulnerabilities detected, but the significant unescaped output presents a considerable risk that requires immediate attention.
Key Concerns
- Unescaped output percentage is high
- AJAX handlers lack capability checks
Wing Suite Security Vulnerabilities
Wing Suite Code Analysis
Output Escaping
Wing Suite Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 16
Maintenance & Trust
Wing Suite Maintenance & Trust
Maintenance Signals
Community Trust
Wing Suite Alternatives
WP Dark Mode – Improve Accessibility with AI Powered Dark Theme
wp-dark-mode
Enable dark mode on WordPress without any coding. Improve site accessibility with a stunning dark theme that improves conversion.
SearchIQ – The Search Solution
searchiq
Our FREE plugin makes your website’s search fast and more relevant. searchIQ helps you to manage content more effectively with real-time analytics.
Dusky Dark Mode – Dark Mode for Gutenberg and Elementor
dusky-dark-mode
Enable Dark Mode on your website & get an awesome user experience with advanced features.
WP Fastest Site Search
wp-fastest-site-search
Replace the default search with ExpertRec's powerful and fully customizable WordPress search plugin.
Audible Site Search
audible-site-search
Audible Site Search adds voice-powered search and AJAX search suggestions to your WordPress site.
Wing Suite Developer Profile
2 plugins · 0 total installs
How We Detect Wing Suite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wing-suite/modules/ajax-search/public/assets/css/ajax-search-public.css/wp-content/plugins/wing-suite/modules/ajax-search/public/assets/js/ajax-search-public.js/wp-content/plugins/wing-suite/modules/dark-mode/public/assets/css/dark-mode-public.css/wp-content/plugins/wing-suite/modules/dark-mode/public/assets/js/dark-mode-public.js/wp-content/plugins/wing-suite/includes/libs/wingcore/wingcore.js/wp-content/plugins/wing-suite/includes/js/wing-suite-public.jswing-suite/includes/libs/wingcore/wingcore.js?ver=wing-suite/includes/js/wing-suite-public.js?ver=HTML / DOM Fingerprints
wing-suite-search-formwing-dark-mode-toggle<!-- Wing Suite: Ajax Search Shortcode -->data-wing-search-idwindow.WingSuiteAjaxSearchwindow.WingSuiteDarkMode/wp-json/wingsuite/v1/search[wing_suite_search_form]