
Wishful Companion Security & Risk Analysis
wordpress.org/plugins/wishful-companionWishful Companion add extra features to all WishfulThemes themes like demo import and other widgets.
Is Wishful Companion Safe to Use in 2026?
Generally Safe
Score 92/100Wishful Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wishful-companion plugin v1.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and performing a significant number of nonce and capability checks. The absence of known CVEs and a clean vulnerability history are also strong indicators of responsible development in the past.
However, several concerns arise from the static analysis. The presence of one AJAX handler without authentication checks presents a direct entry point for potential attackers. Furthermore, two flows with unsanitized paths identified in the taint analysis, although not classified as critical or high severity, suggest potential vulnerabilities if data is not handled rigorously. The use of the `unserialize` function is a known risk vector, especially if the data being unserialized originates from an untrusted source.
In conclusion, while the plugin has a strong track record and implements several security best practices, the identified unprotected AJAX handler and unsanitized taint flows warrant attention. The potential for misuse of `unserialize` also adds a layer of risk. Addressing these specific areas would significantly improve the plugin's overall security.
Key Concerns
- AJAX handler without auth checks
- Flows with unsanitized paths
- Use of dangerous function (unserialize)
Wishful Companion Security Vulnerabilities
Wishful Companion Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Wishful Companion Attack Surface
AJAX Handlers 9
WordPress Hooks 24
Scheduled Events 2
Maintenance & Trust
Wishful Companion Maintenance & Trust
Maintenance Signals
Community Trust
Wishful Companion Alternatives
Popularis Extra
popularis-extra
Popularis Extra add extra features to Popularis theme like demo import, widgets, shortcodes or Elementor widgets.
aThemes Starter Sites
athemes-starter-sites
We've got a full and ever-growing library stocked with ready-made templates for any kind of business.
Bosa Elementor Addons and Templates for WooCommerce
bosa-elementor-for-woocommerce
Elementor Addon with widgets and templates for WooCommerce.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Futurio Extra
futurio-extra
Futurio Extra add extra features to Futurio theme like widgets, WooCommerce options, Elementor widgets, one click demo import and much more.
Wishful Companion Developer Profile
3 plugins · 1K total installs
How We Detect Wishful Companion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wishful-companion/assets/css/dashboard.min.css/wp-content/plugins/wishful-companion/assets/js/dashboard.min.js/wp-content/plugins/wishful-companion/assets/css/common.min.css/wp-content/plugins/wishful-companion/assets/js/common.min.js/wp-content/plugins/wishful-companion/assets/css/builder.min.css/wp-content/plugins/wishful-companion/assets/js/builder.min.js/wp-content/plugins/wishful-companion/assets/css/wizard.min.css/wp-content/plugins/wishful-companion/assets/js/wizard.min.jswishful-companion/assets/css/dashboard.min.css?ver=wishful-companion/assets/js/dashboard.min.js?ver=wishful-companion/assets/css/common.min.css?ver=wishful-companion/assets/js/common.min.js?ver=wishful-companion/assets/css/builder.min.css?ver=wishful-companion/assets/js/builder.min.js?ver=wishful-companion/assets/css/wizard.min.css?ver=wishful-companion/assets/js/wizard.min.js?ver=HTML / DOM Fingerprints
wc-dashboard-contentwc-dashboard-sidebarwc-wizard-stepwc-builder-canvas<!-- wishful_companion_builder_render --><!-- wishful_companion_dashboard_render -->data-wc-builder-elementdata-wc-dashboard-widgetwishfulCompanionDashboardwishfulCompanionBuilder/wp-json/wishful-companion/v1/builder/save/wp-json/wishful-companion/v1/dashboard/widgets[wishful_companion_builder][wishful_companion_dashboard]