WPshed Theme Extras Security & Risk Analysis

wordpress.org/plugins/wpshed-theme-extras

WTE add powerful features to your Theme. It is designed to work with WPshed Themes, but all featured can be used in any other theme.

10 active installs v1.1.0 PHP + WP 4.0+ Updated Unknown
cptportfolioslidertestimonialswidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPshed Theme Extras Safe to Use in 2026?

Generally Safe

Score 100/100

WPshed Theme Extras has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'wpshed-theme-extras' v1.1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests is a significant strength. Furthermore, the presence of nonce and capability checks indicates an effort to secure entry points. The zero known CVEs and the lack of recorded vulnerabilities in its history are also very positive indicators of the plugin's development and maintenance practices.

However, there are areas for improvement that introduce minor risks. A notable concern is the 68% rate of properly escaped output. While a majority of outputs are sanitized, the remaining 32% that are not properly escaped could potentially lead to cross-site scripting (XSS) vulnerabilities if attacker-controlled data is directly outputted without sanitization. The attack surface, while having zero unprotected entry points, consists solely of 10 shortcodes. While these are protected by nonce and capability checks, a large number of shortcodes can still increase the complexity and potential for configuration errors or unforeseen interactions that might bypass security measures.

In conclusion, 'wpshed-theme-extras' v1.1.0 is a plugin with a good foundation of security practices, particularly in its handling of database operations and its lack of historical vulnerabilities. The primary area of concern lies in the output escaping, which warrants attention to ensure all user-facing output is rigorously sanitized to prevent potential XSS flaws. The reliance on shortcodes, while secured, is a factor to monitor as the plugin evolves.

Key Concerns

  • Output escaping is not properly handled for 32% of outputs
  • Attack surface composed entirely of 10 shortcodes
Vulnerabilities
None known

WPshed Theme Extras Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPshed Theme Extras Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
72
152 escaped
Nonce Checks
3
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

68% escaped224 total outputs
Attack Surface

WPshed Theme Extras Attack Surface

Entry Points10
Unprotected0

Shortcodes 10

[grid] inc\functions-shortcodes.php:26
[box] inc\functions-shortcodes.php:43
[button] inc\functions-shortcodes.php:73
[icon] inc\functions-shortcodes.php:93
[divider] inc\functions-shortcodes.php:103
[featured_page] inc\functions-shortcodes.php:192
[featured_posts] inc\functions-shortcodes.php:299
[slider] inc\functions-shortcodes.php:398
[testimonial] inc\functions-shortcodes.php:482
[portfolio] inc\functions-shortcodes.php:590
WordPress Hooks 40
actionwte_help_tabinc\functions-admin-help.php:11
actionadmin_initinc\functions-admin-settings.php:17
actionadmin_noticesinc\functions-admin-settings.php:42
actionwte_settings_tabinc\functions-admin-settings.php:45
actionwte_themes_tabinc\functions-admin-themes.php:11
actionadmin_noticesinc\functions-admin-widgets.php:33
actionadmin_headinc\functions-admin-widgets.php:76
actionwte_widgets_tabinc\functions-admin-widgets.php:79
actionadmin_menuinc\functions-admin.php:29
actionin_widget_forminc\functions-fade-up.php:15
filterwidget_update_callbackinc\functions-fade-up.php:16
filterdynamic_sidebar_paramsinc\functions-fade-up.php:17
actionwp_enqueue_scriptsinc\functions-scripts.php:49
actionwp_footerinc\functions-scripts.php:74
actionadmin_enqueue_scriptsinc\functions-scripts.php:97
actionwidgets_initinc\functions-widgets.php:165
actioninitinc\post-type-portfolio.php:120
actioninitinc\post-type-slides.php:87
actionadd_meta_boxesinc\post-type-slides.php:103
actionsave_postinc\post-type-slides.php:167
actioninitinc\post-type-testimonials.php:87
actionadd_meta_boxesinc\post-type-testimonials.php:103
actionsave_postinc\post-type-testimonials.php:164
actionwidgets_initinc\widgets\call-to-action-widget.php:165
actionwidgets_initinc\widgets\featured-page-widget.php:189
actionwidgets_initinc\widgets\featured-post-widget.php:263
actionwidgets_initinc\widgets\hero-widget.php:176
actionwidgets_initinc\widgets\image-widget.php:114
actionwidgets_initinc\widgets\portfolio-widget.php:151
actionwidgets_initinc\widgets\price-table-widget.php:149
actionwidgets_initinc\widgets\services-widget.php:150
actionwidgets_initinc\widgets\slider-widget.php:163
actionwp_headinc\widgets\social-widget.php:62
actionwidgets_initinc\widgets\social-widget.php:339
actionwidgets_initinc\widgets\testimonial-widget.php:164
actionwidgets_initinc\widgets\user-profile-widget.php:184
actionplugins_loadedwpshed-theme-extras.php:19
filterwidget_textwpshed-theme-extras.php:96
actionafter_setup_themewpshed-theme-extras.php:169
filterbody_classwpshed-theme-extras.php:187
Maintenance & Trust

WPshed Theme Extras Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

WPshed Theme Extras Developer Profile

Stefan

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPshed Theme Extras

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpshed-theme-extras/inc/js/admin.js/wp-content/plugins/wpshed-theme-extras/css/admin.css
Script Paths
/wp-content/plugins/wpshed-theme-extras/js/admin.js
Version Parameters
wpshed-theme-extras/css/admin.css?ver=wpshed-theme-extras/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
fadein
JS Globals
wte_vars
FAQ

Frequently Asked Questions about WPshed Theme Extras