
WPshed Theme Extras Security & Risk Analysis
wordpress.org/plugins/wpshed-theme-extrasWTE add powerful features to your Theme. It is designed to work with WPshed Themes, but all featured can be used in any other theme.
Is WPshed Theme Extras Safe to Use in 2026?
Generally Safe
Score 100/100WPshed Theme Extras has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'wpshed-theme-extras' v1.1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests is a significant strength. Furthermore, the presence of nonce and capability checks indicates an effort to secure entry points. The zero known CVEs and the lack of recorded vulnerabilities in its history are also very positive indicators of the plugin's development and maintenance practices.
However, there are areas for improvement that introduce minor risks. A notable concern is the 68% rate of properly escaped output. While a majority of outputs are sanitized, the remaining 32% that are not properly escaped could potentially lead to cross-site scripting (XSS) vulnerabilities if attacker-controlled data is directly outputted without sanitization. The attack surface, while having zero unprotected entry points, consists solely of 10 shortcodes. While these are protected by nonce and capability checks, a large number of shortcodes can still increase the complexity and potential for configuration errors or unforeseen interactions that might bypass security measures.
In conclusion, 'wpshed-theme-extras' v1.1.0 is a plugin with a good foundation of security practices, particularly in its handling of database operations and its lack of historical vulnerabilities. The primary area of concern lies in the output escaping, which warrants attention to ensure all user-facing output is rigorously sanitized to prevent potential XSS flaws. The reliance on shortcodes, while secured, is a factor to monitor as the plugin evolves.
Key Concerns
- Output escaping is not properly handled for 32% of outputs
- Attack surface composed entirely of 10 shortcodes
WPshed Theme Extras Security Vulnerabilities
WPshed Theme Extras Code Analysis
Output Escaping
WPshed Theme Extras Attack Surface
Shortcodes 10
WordPress Hooks 40
Maintenance & Trust
WPshed Theme Extras Maintenance & Trust
Maintenance Signals
Community Trust
WPshed Theme Extras Alternatives
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
wp-testimonial-with-widget
A quick, easy way to add and display responsive, clean client's testimonial on your website using a shortcode, widget or Gutenberg block.
CPO Content Types
cpo-content-types
Add support for special content types in your website, such as a portfolio, features, and slides.
BNE Testimonials
bne-testimonials
Display testimonials and reviews on any page or widget area as list or slider. Upgrade to PRO for additional layouts, themes, submission form, API, ra …
Stax Addons for Elementor
stax-addons-for-elementor
20+ lightweight widgets and enhancements for Elementor. Modular, fast, and zero bloat — assets load only when used.
Elfsight Testimonials Slider
elfsight-testimonials-slider
Level up your website credibility with trustworthy testimonials
WPshed Theme Extras Developer Profile
1 plugin · 10 total installs
How We Detect WPshed Theme Extras
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpshed-theme-extras/inc/js/admin.js/wp-content/plugins/wpshed-theme-extras/css/admin.css/wp-content/plugins/wpshed-theme-extras/js/admin.jswpshed-theme-extras/css/admin.css?ver=wpshed-theme-extras/js/admin.js?ver=HTML / DOM Fingerprints
fadeinwte_vars