XT Corporate ToolKit Security & Risk Analysis

wordpress.org/plugins/xt-corporate-toolkit

Adding Custom post type and Taxonomy functionality to themes.

90 active installs v1.0.2 PHP + WP 3.9+ Updated Nov 16, 2017
businesscorporatetoolkit
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is XT Corporate ToolKit Safe to Use in 2026?

Generally Safe

Score 85/100

XT Corporate ToolKit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "xt-corporate-toolkit" plugin v1.0.2 exhibits a strong initial security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history is a significant positive indicator, suggesting a generally well-maintained codebase. Furthermore, the static analysis reveals a zero attack surface through common entry points like AJAX handlers, REST API routes, and shortcodes, which is excellent. The code also demonstrates good practices by not using dangerous functions, performing file operations, or making external HTTP requests.

However, there are a few areas that warrant attention. While the total number of output operations is small, the fact that 40% of them are not properly escaped represents a potential risk for Cross-Site Scripting (XSS) vulnerabilities, especially if any of these outputs handle user-supplied data. The complete absence of nonce and capability checks, while seemingly protected by a zero attack surface, means that if any new entry points were inadvertently introduced or if the environment changed, there would be no built-in protection. The taint analysis showing zero flows is reassuring but is based on a very limited scope (0 flows analyzed).

In conclusion, the plugin's current security is good due to its lack of known vulnerabilities and a limited attack surface. The primary concern lies in the unescaped output, which should be addressed to prevent potential XSS. The lack of any checks across all entry points, even though currently zero, represents a potential weakness should the attack surface expand in future updates.

Key Concerns

  • Unescaped output detected
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

XT Corporate ToolKit Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

XT Corporate ToolKit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped15 total outputs
Attack Surface

XT Corporate ToolKit Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitxt-corporate-toolkit.php:104
actionwp_headxt-corporate-toolkit.php:242
Maintenance & Trust

XT Corporate ToolKit Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 16, 2017
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

XT Corporate ToolKit Developer Profile

Xylus Themes

13 plugins · 110K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
105 days
View full developer profile
Detection Fingerprints

How We Detect XT Corporate ToolKit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/xt-corporate-toolkit/js/custom.js/wp-content/plugins/xt-corporate-toolkit/js/map-custom.js

HTML / DOM Fingerprints

JS Globals
googleinit
Shortcode Output
<div id="map"></div>
FAQ

Frequently Asked Questions about XT Corporate ToolKit