
The Ultimate WordPress Toolkit – WP Extended Security & Risk Analysis
wordpress.org/plugins/wpextendedSMTP Email, Maintenance Mode, Duplicate Posts & Pages, Duplicate menu, Code Snippets, SVG File upload, Disable Gutenberg, Limit Login Attempts &am …
Is The Ultimate WordPress Toolkit – WP Extended Safe to Use in 2026?
Generally Safe
Score 90/100The Ultimate WordPress Toolkit – WP Extended has a strong security track record. Known vulnerabilities have been patched promptly.
The "wpextended" plugin v3.2.4 presents a mixed security posture. While it exhibits good practices such as a relatively small attack surface with all identified entry points having authentication checks and a high percentage of SQL queries using prepared statements and proper output escaping, there are several areas of concern. The presence of the "unserialize" dangerous function, multiple flows with unsanitized paths identified in taint analysis, and one high severity taint flow indicate potential for serious vulnerabilities if inputs are not meticulously validated. The plugin's history of 16 known CVEs, with a significant number of high and medium severity issues including SQL Injection, Cross-site Scripting, Path Traversal, and Authorization Bypass, is a substantial red flag. The fact that there are currently no unpatched CVEs is positive, but the sheer volume and types of past vulnerabilities suggest a recurring pattern of security weaknesses that require ongoing vigilance. The plugin's reliance on the Select2 library could also pose a risk if that library is outdated or has known vulnerabilities.
Key Concerns
- Dangerous function: unserialize present
- Flows with unsanitized paths found
- High severity taint flow found
- History of 16 known CVEs
- History of 5 high severity CVEs
- History of 11 medium severity CVEs
- Common vulnerability type: SQL Injection
- Common vulnerability type: XSS
- Common vulnerability type: Path Traversal
- Common vulnerability type: Authorization Bypass
- Bundled library: Select2
The Ultimate WordPress Toolkit – WP Extended Security Vulnerabilities
CVEs by Year
Severity Breakdown
16 total CVEs
WP Extended <= 3.0.15 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The Ultimate WordPress Toolkit – WP Extended <= 3.0.14 - Reflected Cross-Site Scripting
The Ultimate WordPress Toolkit – WP Extended <= 3.0.13 - Missing Authorization to Unauthenticated Post Order Manipulation
The Ultimate WordPress Toolkit – WP Extended <= 3.0.12 - Unauthenticated SQL Injection via Login Attempts Module
The Ultimate WordPress Toolkit – WP Extended <= 3.0.11 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
The Ultimate WordPress Toolkit – WP Extended <= 3.0.11 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution
The Ultimate WordPress Toolkit – WP Extended <= 3.0.9 - Reflected Cross-Site Scripting
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Reflected Cross-Site Scripting
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via selected_option
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Directory Traversal to Authenticated (Subscriber+) Arbitrary File Download
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via page
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Authenticated (Subscriber+) Sensitive Information Exposure
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Authenticated (Subscriber+) Arbitrary Options Update
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Insecure Direct Object Reference
The Ultimate WordPress Toolkit – WP Extended <= 3.0.8 - Missing Authorization to Admin Username Change
The Ultimate WordPress Toolkit – WP Extended <= 2.4.7 - Unauthenticated Stored Cross-Site Scripting
The Ultimate WordPress Toolkit – WP Extended Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
The Ultimate WordPress Toolkit – WP Extended Attack Surface
AJAX Handlers 2
WordPress Hooks 198
Maintenance & Trust
The Ultimate WordPress Toolkit – WP Extended Maintenance & Trust
Maintenance Signals
Community Trust
The Ultimate WordPress Toolkit – WP Extended Alternatives
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider
fluent-smtp
The Ultimate Forever Free Mail SMTP Plugin for WordPress. Connect with any SMTP, SendGrid, Mailgun, Amazon SES, Brevo, Postmark, Sparkpost, Google...
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
The Ultimate WordPress Toolkit – WP Extended Developer Profile
1 plugin · 700 total installs
How We Detect The Ultimate WordPress Toolkit – WP Extended
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpextended/includes/framework/assets/css/wpextended-framework.css/wp-content/plugins/wpextended/includes/framework/assets/js/wpextended-framework.js/wp-content/plugins/wpextended/assets/css/wpextended-admin.css/wp-content/plugins/wpextended/assets/js/wpextended-admin.js/wp-content/plugins/wpextended/includes/framework/assets/js/wpextended-framework.js/wp-content/plugins/wpextended/assets/js/wpextended-admin.jswpextended/includes/framework/assets/css/wpextended-framework.css?ver=wpextended/includes/framework/assets/js/wpextended-framework.js?ver=wpextended/assets/css/wpextended-admin.css?ver=wpextended/assets/js/wpextended-admin.js?ver=HTML / DOM Fingerprints
wpextended-frameworkwpextended-admin-wrap<!-- WP Extended Settings Framework --><!-- WP Extended Admin Wrap -->data-wpextended-fielddata-wpextended-nonceWpextendedFrameworkwpextended_admin_params/wp-json/wpextended/v1/