
WP/LR Theme Assistant Security & Risk Analysis
wordpress.org/plugins/wplr-theme-assistantWP/LR Theme Assistant is an extension for WP/LR Sync that allows you to create mappings between the WP/LR Sync API and the technical structure of your …
Is WP/LR Theme Assistant Safe to Use in 2026?
Generally Safe
Score 85/100WP/LR Theme Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin exhibits a poor security posture due to significant concerns identified in its static analysis. The absence of any authentication or capability checks on its two AJAX entry points creates a substantial attack surface that is completely unprotected. Furthermore, the plugin fails to properly escape any of its output, leading to a high risk of Cross-Site Scripting (XSS) vulnerabilities. The fact that 100% of its single SQL query is not using prepared statements also presents a risk of SQL injection. While there is no recorded vulnerability history, this lack of historical issues does not mitigate the severe coding practices identified in the current version. The plugin has critical weaknesses in handling user input and output, and its direct exposure of AJAX handlers without any security checks is a major flaw. The absence of taint analysis results is noted, but the other identified issues are sufficient to warrant significant caution.
Key Concerns
- AJAX handlers without auth checks
- SQL queries not using prepared statements
- Output not properly escaped
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
WP/LR Theme Assistant Security Vulnerabilities
WP/LR Theme Assistant Code Analysis
SQL Query Safety
Output Escaping
WP/LR Theme Assistant Attack Surface
AJAX Handlers 2
WordPress Hooks 25
Maintenance & Trust
WP/LR Theme Assistant Maintenance & Trust
Maintenance Signals
Community Trust
WP/LR Theme Assistant Alternatives
Meow Gallery
meow-gallery
Tired of slow, bloated gallery plugins? You've earned a coffee ☺️ Polished, beautiful galleries that are blazing fast.
Angie – Agentic AI for WordPress (Beta)
angie
Angie Code: Your expert WordPress developer, powered by AI. Build anything you can imagine without writing a single line of code.
Assistant – Every Day Productivity Apps
assistant
Assistant is a plugin that allows you to work more efficiently. It provides you shortcuts to common admin tasks on the front-end of your website.
WProofreader spell & grammar check plugin for WordPress
webspellchecker
WProofreader checks spelling, grammar, and style in real-time while editing in WordPress.
QA Assistants – Driven by data
qa-heatmap-analytics
Let your data speak — assistants with different perspectives help you understand your site, alongside heatmaps and replays.
WP/LR Theme Assistant Developer Profile
27 plugins · 371K total installs
How We Detect WP/LR Theme Assistant
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wplr-theme-assistant/css/admin.css/wp-content/plugins/wplr-theme-assistant/css/style.css/wp-content/plugins/wplr-theme-assistant/js/admin.js/wp-content/plugins/wplr-theme-assistant/js/script.js/wp-content/plugins/wplr-theme-assistant/js/admin.js/wp-content/plugins/wplr-theme-assistant/js/script.jswplr-theme-assistant/css/admin.css?ver=wplr-theme-assistant/css/style.css?ver=wplr-theme-assistant/js/admin.js?ver=wplr-theme-assistant/js/script.js?ver=HTML / DOM Fingerprints
wplr-sync-infowplrsync-media-data-wplr-mapping-idWPLR_MappingsAPIwplr_mappings_ajax_object/wp-json/wplr/v1/mappings