Wing Suite Security & Risk Analysis

wordpress.org/plugins/wing-suite

Your all-in-one WordPress enhancement suite — starting with Dark Mode and AJAX Search modules. More modules coming soon.

0 active installs v1.0.0 PHP 7.4+ WP 6.5+ Updated Sep 13, 2025
accessibilityajax-searchdark-modesite-searchsite-tools
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wing Suite Safe to Use in 2026?

Generally Safe

Score 100/100

Wing Suite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "wing-suite" v1.0.0 plugin exhibits a generally positive security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are strong indicators of secure coding practices. The presence of a nonce check is also a positive sign for handling AJAX requests, though the lack of capability checks on the AJAX handlers is a notable concern.

The main area of concern arises from the output escaping. With 53% of outputs not properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis did not reveal any specific issues, the high percentage of unescaped output presents a latent threat that could be exploited if malicious data is introduced into these output flows.

The plugin has no recorded vulnerability history, which is excellent. This suggests a good track record and potentially a diligent development process. However, the absence of past vulnerabilities does not negate the risks identified in the static analysis, particularly concerning the unescaped output. The overall conclusion is that "wing-suite" v1.0.0 has a solid foundation with no critical code-level vulnerabilities detected, but the significant unescaped output presents a considerable risk that requires immediate attention.

Key Concerns

  • Unescaped output percentage is high
  • AJAX handlers lack capability checks
Vulnerabilities
None known

Wing Suite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Wing Suite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
40
46 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

53% escaped86 total outputs
Attack Surface

Wing Suite Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 2

authwp_ajax_wingsuite_search_ajax_searchmodules\ajax-search\public\ajax-search-public.php:22
noprivwp_ajax_wingsuite_search_ajax_searchmodules\ajax-search\public\ajax-search-public.php:23

Shortcodes 2

[wingsuite_search] modules\ajax-search\public\ajax-search-public.php:95
[wingsuite_dark_mode] modules\dark-mode\public\dark-mode-public.php:55
WordPress Hooks 16
actionadmin_menuadmin\class-wing-suite-admin.php:10
actionadmin_enqueue_scriptsadmin\class-wing-suite-admin.php:16
actionadmin_enqueue_scriptsadmin\class-wing-suite-admin.php:17
actioninitmodules\ajax-search\includes\ajax-search.php:12
actionadmin_menumodules\ajax-search\includes\ajax-search.php:13
actioninitmodules\ajax-search\public\ajax-search-public.php:17
actionwp_enqueue_scriptsmodules\ajax-search\public\ajax-search-public.php:19
actionwp_enqueue_scriptsmodules\ajax-search\public\ajax-search-public.php:20
filterwp_nav_menu_itemsmodules\ajax-search\public\ajax-search-public.php:25
actionwp_footermodules\dark-mode\public\dark-mode-public.php:26
filterwp_nav_menu_itemsmodules\dark-mode\public\dark-mode-public.php:29
actioninitmodules\dark-mode\public\dark-mode-public.php:34
actionwp_enqueue_scriptsmodules\dark-mode\public\dark-mode-public.php:48
actionwp_enqueue_scriptsmodules\dark-mode\public\dark-mode-public.php:49
actionwp_headmodules\dark-mode\public\dark-mode-public.php:50
actionplugins_loadedwing-suite.php:57
Maintenance & Trust

Wing Suite Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 13, 2025
PHP min version7.4
Downloads179

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Wing Suite Developer Profile

wingdevs

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wing Suite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wing-suite/modules/ajax-search/public/assets/css/ajax-search-public.css/wp-content/plugins/wing-suite/modules/ajax-search/public/assets/js/ajax-search-public.js/wp-content/plugins/wing-suite/modules/dark-mode/public/assets/css/dark-mode-public.css/wp-content/plugins/wing-suite/modules/dark-mode/public/assets/js/dark-mode-public.js
Script Paths
/wp-content/plugins/wing-suite/includes/libs/wingcore/wingcore.js/wp-content/plugins/wing-suite/includes/js/wing-suite-public.js
Version Parameters
wing-suite/includes/libs/wingcore/wingcore.js?ver=wing-suite/includes/js/wing-suite-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
wing-suite-search-formwing-dark-mode-toggle
HTML Comments
<!-- Wing Suite: Ajax Search Shortcode -->
Data Attributes
data-wing-search-id
JS Globals
window.WingSuiteAjaxSearchwindow.WingSuiteDarkMode
REST Endpoints
/wp-json/wingsuite/v1/search
Shortcode Output
[wing_suite_search_form]
FAQ

Frequently Asked Questions about Wing Suite