
Template Manager by WordPress Monsters Security & Risk Analysis
wordpress.org/plugins/wpm-template-managerThis is a temlate manager plugin for easy WordPress development from scratch when you are use Page Builders plugins.
Is Template Manager by WordPress Monsters Safe to Use in 2026?
Generally Safe
Score 85/100Template Manager by WordPress Monsters has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpm-template-manager" plugin v1.1.0 demonstrates a generally strong security posture based on the provided static analysis. The complete absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests are significant strengths. Furthermore, the plugin has no recorded CVEs, indicating a history of relative security. The presence of nonce checks, albeit limited, is also a positive sign. However, a concerning area is the very low percentage of properly escaped output (18%). This suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data, if not properly handled, could be injected into the output displayed to users. While taint analysis found no critical or high severity flows, the low output escaping rate is a pervasive concern that could lead to exploitable vulnerabilities in various scenarios, especially if any user input is reflected directly in the frontend or admin area without adequate sanitization.
Despite the low output escaping, the overall security is decent due to the lack of other common vulnerabilities and a clean history. The primary weakness lies in the potential for XSS due to insufficient output sanitization. The absence of a large attack surface (no AJAX handlers, REST API routes, shortcodes, or cron events without auth checks) further bolsters its security. The plugin's strengths in preventing SQL injection and other common attack vectors are notable, but the XSS risk due to poor output escaping should not be overlooked and warrants attention for future updates.
Key Concerns
- Low percentage of properly escaped output
Template Manager by WordPress Monsters Security Vulnerabilities
Template Manager by WordPress Monsters Code Analysis
Output Escaping
Data Flow Analysis
Template Manager by WordPress Monsters Attack Surface
WordPress Hooks 11
Maintenance & Trust
Template Manager by WordPress Monsters Maintenance & Trust
Maintenance Signals
Community Trust
Template Manager by WordPress Monsters Alternatives
Extendify
extendify
The best WordPress templates, pattern, and layout library with 1,000+ designs built for the Gutenberg block editor.
Blog Designer
blog-designer
Allows you to create and modify your blog page with 15 unique blog layouts. A quick and easy way to change blog page designs with so easy steps.
WP Blog and Widgets
wp-blog-and-widgets
A quick, easy way to add a Blog custom post type, Blog widget to WordPress. Also, work with the Gutenberg shortcode block.
Layouts for WPBakery
layouts-for-wpbakery
Layouts for WPBakery is a beautifully designed free layout for famous WordPress WPBakery page builders.
WP Layouts
wp-layouts
Save, store and import layouts instantly, all in one place with the click of a button!
Template Manager by WordPress Monsters Developer Profile
4 plugins · 130 total installs
How We Detect Template Manager by WordPress Monsters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpm-template-manager/assets/css/admin-template-manager.cssHTML / DOM Fingerprints
debug-toolnotice-success[wpm-template-content]