
XT Corporate ToolKit Security & Risk Analysis
wordpress.org/plugins/xt-corporate-toolkitAdding Custom post type and Taxonomy functionality to themes.
Is XT Corporate ToolKit Safe to Use in 2026?
Generally Safe
Score 85/100XT Corporate ToolKit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "xt-corporate-toolkit" plugin v1.0.2 exhibits a strong initial security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history is a significant positive indicator, suggesting a generally well-maintained codebase. Furthermore, the static analysis reveals a zero attack surface through common entry points like AJAX handlers, REST API routes, and shortcodes, which is excellent. The code also demonstrates good practices by not using dangerous functions, performing file operations, or making external HTTP requests.
However, there are a few areas that warrant attention. While the total number of output operations is small, the fact that 40% of them are not properly escaped represents a potential risk for Cross-Site Scripting (XSS) vulnerabilities, especially if any of these outputs handle user-supplied data. The complete absence of nonce and capability checks, while seemingly protected by a zero attack surface, means that if any new entry points were inadvertently introduced or if the environment changed, there would be no built-in protection. The taint analysis showing zero flows is reassuring but is based on a very limited scope (0 flows analyzed).
In conclusion, the plugin's current security is good due to its lack of known vulnerabilities and a limited attack surface. The primary concern lies in the unescaped output, which should be addressed to prevent potential XSS. The lack of any checks across all entry points, even though currently zero, represents a potential weakness should the attack surface expand in future updates.
Key Concerns
- Unescaped output detected
- No nonce checks on entry points
- No capability checks on entry points
XT Corporate ToolKit Security Vulnerabilities
XT Corporate ToolKit Code Analysis
Output Escaping
XT Corporate ToolKit Attack Surface
WordPress Hooks 2
Maintenance & Trust
XT Corporate ToolKit Maintenance & Trust
Maintenance Signals
Community Trust
XT Corporate ToolKit Alternatives
Business One ToolKit
business-one-toolkit
Adding Custom post type and Taxonomy functionality to themes.
Partners
partners
Creates a fenced membership area with private content.
Resource Library
resource-library
Document management at its finest. Easily create and manage a document download and viewing area for your website.
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
XT Corporate ToolKit Developer Profile
13 plugins · 110K total installs
How We Detect XT Corporate ToolKit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xt-corporate-toolkit/js/custom.js/wp-content/plugins/xt-corporate-toolkit/js/map-custom.jsHTML / DOM Fingerprints
googleinit<div id="map"></div>