Wowholic CORE Security & Risk Analysis

wordpress.org/plugins/wowholic-core

CORE makes you faster and more efficient when developing custom WordPress sites.

40 active installs v1.1.3 PHP 7.0+ WP 5.6+ Updated Dec 4, 2025
custom-themesdevelopmentefficiencyproductivityutility
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wowholic CORE Safe to Use in 2026?

Generally Safe

Score 100/100

Wowholic CORE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "wowholic-core" v1.1.3 plugin exhibits a strong security posture based on the provided static analysis. All identified entry points, including a shortcode, appear to be protected by capability checks. The code demonstrates excellent practices in database interaction, with 100% of SQL queries utilizing prepared statements. Furthermore, all output is properly escaped, and there are no detected dangerous functions, file operations, or external HTTP requests, indicating a low risk of common vulnerabilities such as SQL injection, arbitrary file access, or cross-site scripting (XSS) originating from these areas. The absence of any recorded CVEs further reinforces this positive assessment.

While the plugin benefits from robust coding practices, the lack of nonce checks on its single shortcode entry point presents a potential, albeit minor, concern. Although capability checks are in place, nonce validation is a critical defense against Cross-Site Request Forgery (CSRF) attacks, especially for actions that might be triggered by user interaction. The taint analysis also reports zero flows, which is a good sign, but it's worth noting that this is based on zero analyzed flows, meaning the analysis might not have been exhaustive or comprehensive in uncovering all potential issues.

In conclusion, "wowholic-core" v1.1.3 appears to be a well-secured plugin with a clean vulnerability history and good adherence to secure coding principles. The primary area for improvement would be the implementation of nonce checks on its shortcode to mitigate the risk of CSRF. However, given the other security measures in place, the overall risk is currently assessed as low.

Key Concerns

  • Shortcode entry point without nonce check
Vulnerabilities
None known

Wowholic CORE Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wowholic CORE Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

100% escaped14 total outputs
Attack Surface

Wowholic CORE Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[email] includes\actions\general.php:98
WordPress Hooks 39
actionacf/initincludes\actions\acf.php:7
filterget_the_excerptincludes\actions\acf.php:22
filteracf/format_value/type=textareaincludes\actions\acf.php:23
filteracf/format_value/type=textincludes\actions\acf.php:24
filteracf/settings/show_adminincludes\actions\acf.php:31
actioninitincludes\actions\cleanup.php:8
actionwp_enqueue_scriptsincludes\actions\cleanup.php:11
filterthe_generatorincludes\actions\cleanup.php:14
filterwp_headincludes\actions\cleanup.php:17
actionwp_headincludes\actions\cleanup.php:20
actionwp_enqueue_scriptsincludes\actions\cleanup.php:23
filterscript_loader_tagincludes\actions\filters.php:20
actionadmin_menuincludes\actions\general.php:7
actionadmin_initincludes\actions\general.php:24
filtercomments_openincludes\actions\general.php:45
filterpings_openincludes\actions\general.php:46
filtercomments_arrayincludes\actions\general.php:49
actionadmin_menuincludes\actions\general.php:52
actioninitincludes\actions\general.php:58
actionadmin_initincludes\actions\general.php:69
actionadmin_menuincludes\actions\general.php:78
filterupload_size_limitincludes\actions\general.php:87
actioninitincludes\actions\general.php:126
actiontemplate_redirectincludes\actions\general.php:140
actionwp_headincludes\actions\grid.php:221
actionwp_footerincludes\actions\grid.php:222
actionwp_enqueue_scriptsincludes\actions\layout.php:7
actiontemplate_redirectincludes\actions\redirects.php:7
actiontemplate_redirectincludes\actions\redirects.php:22
filtertiny_mce_before_initincludes\actions\tinymce.php:7
filtermce_buttons_2includes\actions\tinymce.php:39
filtermce_buttonsincludes\actions\tinymce.php:50
filtermce_buttons_2includes\actions\tinymce.php:51
filtertiny_mce_before_initincludes\actions\tinymce.php:68
filtertiny_mce_before_initincludes\actions\tinymce.php:84
actionafter_setup_themeincludes\boot.php:8
actionadmin_enqueue_scriptsincludes\boot.php:16
actioncarbon_fields_register_fieldsincludes\settings-page.php:6
actioncarbon_fields_fields_registeredincludes\settings-page.php:225
Maintenance & Trust

Wowholic CORE Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Wowholic CORE Developer Profile

Wowholic

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wowholic CORE

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wowholic-core/assets/css/main.css/wp-content/plugins/wowholic-core/assets/js/main.js/wp-content/plugins/wowholic-core/assets/js/spacing.min.js
Script Paths
/wp-content/plugins/wowholic-core/assets/js/spacing.min.js/wp-content/plugins/wowholic-core/assets/js/main.js

HTML / DOM Fingerprints

CSS Classes
wowcore-gridwowcore-grid_containerwowcore-grid_rowwowcore-grid_colwowcore-toggle-gridis-active
Data Attributes
data-wowcore-grid
FAQ

Frequently Asked Questions about Wowholic CORE