
WP Child Theme Generator Security & Risk Analysis
wordpress.org/plugins/wp-child-theme-generatorWP Child Theme Generator is an easy solution to all your WordPress child theme creating problems!
Is WP Child Theme Generator Safe to Use in 2026?
Generally Safe
Score 96/100WP Child Theme Generator has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of wp-child-theme-generator v1.1.4 shows a generally strong security posture with a very small attack surface, no reported dangerous functions, and a high percentage of properly escaped output. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with exposed entry points is a significant strength. Furthermore, all SQL queries utilize prepared statements, and there are no detected taint flows with unsanitized paths. However, the plugin has a history of two known CVEs, including one critical vulnerability previously related to missing authorization and unrestricted file uploads. While there are no currently unpatched vulnerabilities, this history indicates a past tendency towards issues that could be exploited by authenticated or unauthenticated attackers if not properly addressed.
Despite the positive findings in the current static analysis, the vulnerability history is a significant concern. The presence of past critical vulnerabilities, even if patched, suggests a need for continued vigilance. The critical vulnerability type of 'Missing Authorization' could indicate a weakness in how the plugin verifies user permissions for certain actions, and 'Unrestricted Upload of File with Dangerous Type' points to a risk of malicious file execution if uploads are not strictly validated. While the current version seems to have addressed these, the past occurrences warrant a higher degree of scrutiny.
Key Concerns
- Past critical vulnerability history
- Past medium vulnerability history
- Past unrestricted file upload vulnerability
- Past missing authorization vulnerability
WP Child Theme Generator Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Child Theme Generator <= 1.1.1 - Missing Authorization to Unauthenticated Child Theme Creation/Activation
WP Child Theme Generator <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload
WP Child Theme Generator Code Analysis
Output Escaping
Data Flow Analysis
WP Child Theme Generator Attack Surface
WordPress Hooks 9
Maintenance & Trust
WP Child Theme Generator Maintenance & Trust
Maintenance Signals
Community Trust
WP Child Theme Generator Alternatives
Childify Me
childify-me
Create a child-theme from the Theme Customizer.
Generate Child Theme
generate-child-theme
Create child themes of any WordPress themes effortlessly with Generate Child Theme.
Child My Theme
bss-child-my-theme
Child My Theme is an easy solution to create all your child theme!
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
Child Theme Configurator
child-theme-configurator
When using the Customizer is not enough - Create a child theme from your installed themes and customize styles, templates, functions and more.
WP Child Theme Generator Developer Profile
47 plugins · 26K total installs
How We Detect WP Child Theme Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-child-theme-generator/assets/js/custom.js/wp-content/plugins/wp-child-theme-generator/assets/css/admin-style.css/wp-content/plugins/wp-child-theme-generator/assets/js/wpctg-pointer.jsHTML / DOM Fingerprints
wpctgPointer