
Wowholic CORE Security & Risk Analysis
wordpress.org/plugins/wowholic-coreCORE makes you faster and more efficient when developing custom WordPress sites.
Is Wowholic CORE Safe to Use in 2026?
Generally Safe
Score 100/100Wowholic CORE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wowholic-core" v1.1.3 plugin exhibits a strong security posture based on the provided static analysis. All identified entry points, including a shortcode, appear to be protected by capability checks. The code demonstrates excellent practices in database interaction, with 100% of SQL queries utilizing prepared statements. Furthermore, all output is properly escaped, and there are no detected dangerous functions, file operations, or external HTTP requests, indicating a low risk of common vulnerabilities such as SQL injection, arbitrary file access, or cross-site scripting (XSS) originating from these areas. The absence of any recorded CVEs further reinforces this positive assessment.
While the plugin benefits from robust coding practices, the lack of nonce checks on its single shortcode entry point presents a potential, albeit minor, concern. Although capability checks are in place, nonce validation is a critical defense against Cross-Site Request Forgery (CSRF) attacks, especially for actions that might be triggered by user interaction. The taint analysis also reports zero flows, which is a good sign, but it's worth noting that this is based on zero analyzed flows, meaning the analysis might not have been exhaustive or comprehensive in uncovering all potential issues.
In conclusion, "wowholic-core" v1.1.3 appears to be a well-secured plugin with a clean vulnerability history and good adherence to secure coding principles. The primary area for improvement would be the implementation of nonce checks on its shortcode to mitigate the risk of CSRF. However, given the other security measures in place, the overall risk is currently assessed as low.
Key Concerns
- Shortcode entry point without nonce check
Wowholic CORE Security Vulnerabilities
Wowholic CORE Code Analysis
Bundled Libraries
Output Escaping
Wowholic CORE Attack Surface
Shortcodes 1
WordPress Hooks 39
Maintenance & Trust
Wowholic CORE Maintenance & Trust
Maintenance Signals
Community Trust
Wowholic CORE Alternatives
Simple Dashboard Todo
dash-todo
A simple todo management plugin for WordPress site admins. Stay consistent and never forget anything.
QuickStart
quickstart
This plugin is no longer being developed.
B-Productiv Lite
b-productiv-lite
The purpose of this plugin is to improve business productivity for small businesses and organizations especially those with employees and contractors …
Development Mode
development-mode
Uses Sunrise theme on Dashboard and Frontend to visually represent development mode
"Safe WP Updates" by WP Boom
safe-wp-updates-by-wp-boom
A site cloning and visual testing tool that allows creation of development sites for WordPress update testing.
Wowholic CORE Developer Profile
1 plugin · 40 total installs
How We Detect Wowholic CORE
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wowholic-core/assets/css/main.css/wp-content/plugins/wowholic-core/assets/js/main.js/wp-content/plugins/wowholic-core/assets/js/spacing.min.js/wp-content/plugins/wowholic-core/assets/js/spacing.min.js/wp-content/plugins/wowholic-core/assets/js/main.jsHTML / DOM Fingerprints
wowcore-gridwowcore-grid_containerwowcore-grid_rowwowcore-grid_colwowcore-toggle-gridis-activedata-wowcore-grid