Wyvern Toolkit Security & Risk Analysis

wordpress.org/plugins/wyvern-toolkit

Wyvern Toolkit is a fast, reliable, and affordable professional WordPress plugin that does everything you need to create and manage an amazing website …

0 active installs v1.0.6 PHP 7.2+ WP 5.8+ Updated Feb 6, 2023
custom-scriptsgoogle-fontsimport-exportmaintenance-modepreloader
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wyvern Toolkit Safe to Use in 2026?

Generally Safe

Score 85/100

Wyvern Toolkit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The Wyvern Toolkit plugin, in version 1.0.6, exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, critical or otherwise, suggests a history of responsible development or effective patching. The static analysis reveals a contained attack surface with all identified entry points (AJAX handlers) protected by authorization checks. Furthermore, the code demonstrates good practices regarding SQL query preparation, with a high percentage of queries utilizing prepared statements. Output escaping, while not perfect, also shows a reasonable level of diligence, with a majority of outputs being properly escaped.

However, there are minor areas for improvement. While no critical or high-severity taint flows were detected, the fact that zero taint flows were analyzed limits the confidence in this assessment. Additionally, the 25% of SQL queries not using prepared statements, although likely a small number in absolute terms, represents a potential risk if these queries handle user-supplied input without sufficient sanitization. Similarly, the 30% of outputs that are not properly escaped could lead to cross-site scripting vulnerabilities if user-supplied data is involved. Despite these minor concerns, the plugin appears to be developed with security in mind, and the lack of historical vulnerabilities is a positive indicator.

Key Concerns

  • SQL queries not using prepared statements
  • Output escaping not properly handled
Vulnerabilities
None known

Wyvern Toolkit Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Wyvern Toolkit Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
6 prepared
Unescaped Output
31
73 escaped
Nonce Checks
6
Capability Checks
8
File Operations
28
External Requests
3
Bundled Libraries
0

SQL Query Safety

75% prepared8 total queries

Output Escaping

70% escaped104 total outputs
Attack Surface

Wyvern Toolkit Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_wyvern_toolkit_pointer_dismiss_noticeincludes\Assets.php:33
authwp_ajax_wyvern_toolkit_import_export_importermodules\import-export\inc\class-ajax.php:22
authwp_ajax_wyvern_toolkit_import_export_exportermodules\import-export\inc\class-ajax.php:23
WordPress Hooks 20
filterwyvern_toolkit_filter_admin_localizeincludes\Abstracts\ModuleConfigs.php:53
actionwp_enqueue_scriptsincludes\Abstracts\ModuleConfigs.php:55
actionadmin_enqueue_scriptsincludes\Abstracts\ModuleConfigs.php:56
actionrest_api_initincludes\API\API.php:58
actionadmin_enqueue_scriptsincludes\Assets.php:32
actioninitincludes\DownloadManager.php:25
actionadmin_initincludes\Stats.php:134
actionwp_version_checkincludes\Stats.php:137
actionupgrader_process_completeincludes\WyvernToolkit.php:40
filterwyvern_toolkit_filter_custom-scripts_api_updatemodules\custom-scripts\inc\functions.php:102
filterwyvern_toolkit_filter_custom-scripts_api_querymodules\custom-scripts\inc\functions.php:113
filterwyvern_toolkit_filter_google-fonts_api_querymodules\google-fonts\inc\functions.php:355
actionwp_headmodules\google-fonts\inc\functions.php:390
actionwp_scheduled_deletemodules\import-export\inc\functions.php:28
filterimport_post_meta_keymodules\import-export\inc\importers\content-importer\class-wp-import.php:77
filterhttp_request_timeoutmodules\import-export\inc\importers\content-importer\class-wp-import.php:78
actionadmin_initmodules\import-export\inc\importers\content-importer\init.php:40
actionwp_body_openmodules\preloader\inc\functions.php:19
actionwp_headmodules\preloader\inc\functions.php:73
actionbody_classmodules\preloader\inc\functions.php:79
Maintenance & Trust

Wyvern Toolkit Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 6, 2023
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Wyvern Toolkit Developer Profile

codewyvern

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wyvern Toolkit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wyvern-toolkit/modules/content-visibility/assets/css/content-visibility.css/wp-content/plugins/wyvern-toolkit/modules/forms/assets/css/forms.css/wp-content/plugins/wyvern-toolkit/modules/forms/assets/js/forms.js/wp-content/plugins/wyvern-toolkit/modules/gallery/assets/css/gallery.css/wp-content/plugins/wyvern-toolkit/modules/gallery/assets/js/gallery.js/wp-content/plugins/wyvern-toolkit/modules/helpers/assets/css/helpers.css/wp-content/plugins/wyvern-toolkit/modules/helpers/assets/js/helpers.js/wp-content/plugins/wyvern-toolkit/modules/login-form/assets/css/login-form.css+16 more
Script Paths
/wp-content/plugins/wyvern-toolkit/modules/content-visibility/assets/js/content-visibility.js/wp-content/plugins/wyvern-toolkit/modules/forms/assets/js/forms.js/wp-content/plugins/wyvern-toolkit/modules/gallery/assets/js/gallery.js/wp-content/plugins/wyvern-toolkit/modules/helpers/assets/js/helpers.js/wp-content/plugins/wyvern-toolkit/modules/login-form/assets/js/login-form.js/wp-content/plugins/wyvern-toolkit/modules/posts-slider/assets/js/posts-slider.js+6 more
Version Parameters
wyvern-toolkit/assets/css/admin-style.css?ver=wyvern-toolkit/assets/css/style.css?ver=wyvern-toolkit/assets/js/admin.js?ver=wyvern-toolkit/modules/content-visibility/assets/css/content-visibility.css?ver=wyvern-toolkit/modules/content-visibility/assets/js/content-visibility.js?ver=wyvern-toolkit/modules/forms/assets/css/forms.css?ver=wyvern-toolkit/modules/forms/assets/js/forms.js?ver=wyvern-toolkit/modules/gallery/assets/css/gallery.css?ver=wyvern-toolkit/modules/gallery/assets/js/gallery.js?ver=wyvern-toolkit/modules/helpers/assets/css/helpers.css?ver=wyvern-toolkit/modules/helpers/assets/js/helpers.js?ver=wyvern-toolkit/modules/login-form/assets/css/login-form.css?ver=wyvern-toolkit/modules/login-form/assets/js/login-form.js?ver=wyvern-toolkit/modules/posts-slider/assets/css/posts-slider.css?ver=wyvern-toolkit/modules/posts-slider/assets/js/posts-slider.js?ver=wyvern-toolkit/modules/search/assets/css/search.css?ver=wyvern-toolkit/modules/search/assets/js/search.js?ver=wyvern-toolkit/modules/social-share/assets/css/social-share.css?ver=wyvern-toolkit/modules/social-share/assets/js/social-share.js?ver=wyvern-toolkit/modules/tabs/assets/css/tabs.css?ver=wyvern-toolkit/modules/tabs/assets/js/tabs.js?ver=wyvern-toolkit/modules/testimonial/assets/css/testimonial.css?ver=wyvern-toolkit/modules/testimonial/assets/js/testimonial.js?ver=wyvern-toolkit/modules/woo-checkout-fields/assets/css/woo-checkout-fields.css?ver=wyvern-toolkit/modules/woo-checkout-fields/assets/js/woo-checkout-fields.js?ver=

HTML / DOM Fingerprints

CSS Classes
wyvern-toolkit-notice
HTML Comments
<!-- NOTE: This file is generated automatically. --><!-- Please do not make any changes in this file directly. -->
Data Attributes
data-dismiss-targetdata-wyvern-toolkit-dismissible
JS Globals
wyvernToolkit
FAQ

Frequently Asked Questions about Wyvern Toolkit