
WPS Child Theme Generator Security & Risk Analysis
wordpress.org/plugins/wps-child-theme-generatorCreate your child theme with options. Customize it many options.
Is WPS Child Theme Generator Safe to Use in 2026?
Generally Safe
Score 98/100WPS Child Theme Generator has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the wps-child-theme-generator plugin v1.5.5.2 reveals a generally good security posture regarding its exposed entry points. The plugin has zero AJAX handlers, REST API routes, shortcodes, and cron events, indicating a minimal attack surface. Furthermore, all identified SQL queries use prepared statements, and there are no critical or high severity taint flows found, which are positive signs.
However, several areas raise concerns. The plugin's output escaping is only 25% proper, which can lead to cross-site scripting (XSS) vulnerabilities if untrusted data is directly outputted. While the number of file operations and external HTTP requests is low, their potential impact depends on the context. The presence of a single file operation, external HTTP request, nonce check, and capability check suggests these are implemented, but their security hinges on their correct usage and sanitization of any data handled.
The vulnerability history is a significant concern, with one critical CVE identified in 2019 for 'Improper Limitation of a Pathname to a Restricted Directory' (Path Traversal). Although currently unpatched CVEs are zero, a past critical vulnerability indicates a historical weakness in the plugin's code that attackers could potentially exploit again. The lack of any recent vulnerabilities might suggest improvements, but the historical critical issue warrants caution. Overall, while the plugin has a small attack surface and uses prepared statements, the poor output escaping and the history of a critical vulnerability present tangible risks that need to be addressed.
Key Concerns
- Past critical vulnerability (Path Traversal)
- Low percentage of properly escaped output
WPS Child Theme Generator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPS Child Theme Generator < 1.2 - Directory Traversal
WPS Child Theme Generator Code Analysis
Output Escaping
Data Flow Analysis
WPS Child Theme Generator Attack Surface
WordPress Hooks 4
Maintenance & Trust
WPS Child Theme Generator Maintenance & Trust
Maintenance Signals
Community Trust
WPS Child Theme Generator Alternatives
Child Theme Wizard
child-theme-wizard
Creates a child theme with one click and lets you customise its options.
Child Theme Creator by Orbisius
orbisius-child-theme-creator
Create Child Themes quickly and easily from any theme that you have currently installed on your site/blog.
Generate Child Theme
generate-child-theme
Create child themes of any WordPress themes effortlessly with Generate Child Theme.
ChildMaker AI
childmaker-ai
Create child themes quickly and easily from your WordPress admin panel — clean, simple, and safe.
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
WPS Child Theme Generator Developer Profile
9 plugins · 149K total installs
How We Detect WPS Child Theme Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wps-child-theme-generator/wps-child-theme-generator.php/wp-content/plugins/wps-child-theme-generator/classes/helpers.phpHTML / DOM Fingerprints
<!-- Child theme generated with WPS Child Theme Generator -->/* CSS added with WPS Child Theme Generator *//* Child theme generated with WPS Child Theme Generator */name="b7ectg_parenttheme"name="b7ectg_childtheme"name="b7ectg_themeurl"name="b7ectg_author"name="b7ectg_authurl"name="form_field_nonce"+5 more/wp-json/<option value=""></option>