Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
by Themeisle · Privacy & Consent
Also makes 24 other plugins · 1.8M+ installs across the portfolio →
Add modules: share buttons, header/footer scripts, disable comments, reading progress, custom fonts, custom login & more in one plugin.
90 health vs 66 average across 513 Privacy & Consent plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
92.6K
now · peak 341.6K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
7
releases in the last 12 months
2mo ago
latest release · v3.0.7
150
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 56% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “100K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2017-10-12 · 1,481 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ jenoneilmedia1.3y ago
Thank you for providing this to us!
Read on wp.org ↗ - ★★★★★ yeyocaribe2.5y ago
Work fine, I liked
Read on wp.org ↗ - ★★★★★ TC Lynch2.9y ago
I only seemed to use a couple of the features after testing it for awhile.
Read on wp.org ↗ - ★★★★★ jarlhalla3.0y ago
Thank you for this and great job!
Read on wp.org ↗ - ★★★★★ moncreta3.1y ago
Great sets of modules with excellent responsiveness.
Read on wp.org ↗ - ★★★★★ swevenventuresllp3.3y ago
Great Plugin
Read on wp.org ↗ - ★★★★★ groso3.3y ago
Thanks for your work!
Read on wp.org ↗ - ★★★★★ memo883.4y ago
A solution that satisfies all needs is perfect and demanding for me! Thank you very much!
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- 2026-07-30 Version 3.0.9 Improved Security by sanitizing tags to prevent XSS 3.0.9
- 2026-07-23 Version 3.0.8 Updated dependencies Improved Security Thanks to Shivamani Vastrala for responsibly reporting the issues. 3.0.8
- 2026-06-16 Version 3.0.7 Enhanced security 3.0.7
- 2026-05-25 Version 3.0.6 Updated dependencies 3.0.6
- 2025-12-05 Version 3.0.5 Fixed issue related to Elementor widgets module causing error in Hestia theme 3.0.5
- 2025-12-04 Version 3.0.4 Fixed pagination of Grid Post Type 3.0.4
Known vulnerabilities
via Wordfence Intelligence23 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 6.4 Orbit Fox by ThemeIsle <= 3.0.7 - Authenticated (Author+) Stored Cross-Site Scripting ↗2026-07-27 CVE-2026-16583 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.7 Patched in 3.0.8
- 2026-07-24 CVE-2026-65563 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.7 Patched in 3.0.8
- 2026-06-17 CVE-2026-11358 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.6 Patched in 3.0.7
- Medium · 6.4 Orbit Fox Companion <= 3.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Post Taxonomy ↗2025-11-03 CVE-2025-12045 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.2 Patched in 3.0.3
- Medium · 6.4 Orbit Fox by ThemeIsle <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2025-09-03 CVE-2025-58593 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.0.0 Patched in 3.0.1
- Medium · 6.4 Orbit Fox by ThemeIsle <= 2.10.44 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2025-02-03 CVE-2025-22659 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.44 Patched in 2.10.45
- 2025-01-09 CVE-2024-13183 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.43 Patched in 2.10.44
- 2025-01-09 CVE-2025-0311 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.43 Patched in 2.10.44
- Medium · 6.4 Orbit Fox by ThemeIsle <= 2.10.36 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ↗2024-08-21 CVE-2024-7778 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.36 Patched in 2.10.37
- 2024-06-21 CVE-2024-2484 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.34 Patched in 2.10.35
- 2024-03-07 CVE-2024-2126 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.32 Patched in 2.10.33
- Medium · 6.4 Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2024-02-26 CVE-2024-1323 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.31 Patched in 2.10.32
- 2024-02-26 CVE-2024-1497 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.30 Patched in 2.10.31
- Medium · 6.4 Orbit Fox by ThemeIsle <= 2.10.30 - Authenticated (Contributor+) Stored Cross-Site Scripting ↗2024-02-26 CVE-2024-1499 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.30 Patched in 2.10.31
- 2024-01-15 CVE-2024-0508 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.10.27 Patched in 2.10.28
- Medium · 6.4 Orbit Fox by ThemeIsle <= 2.10.2 - Authenticated (Contributor+) Stored Cross Site Scripting ↗2021-01-12 CVE-2021-24157 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.10.3 Patched in 2.10.3
- 2018-11-12 Missing Authorization Affects <= 2.6.3 Patched in 2.6.4
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 33 languages, 3 at 90% or more · development strings
Plus 9 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-09-30 200K+ → 100K+ down after 827 days in tier
- 2023-06-26 300K+ → 200K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Duplicate Page 3M+ installs · 4.8★ · 1 shared tag B -
CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice) 1M+ installs · 4.8★ · 1 shared tag A
-
Complianz GDPR/CCPA Cookie Consent Banner 1M+ installs · 4.7★ · 1 shared tag A -
AddToAny Share Buttons 300K+ installs · 4.7★ · 1 shared tag A
-
LoginPress | wp-login Custom Login Page Customizer 200K+ installs · 4.8★ · 1 shared tag A -
WPConsent – Cookie Banner & Cookie Consent for Privacy Compliance (GDPR / CCPA / EU Compliance Cookie Notice) 200K+ installs · 4.7★ · 1 shared tag A
Embed this report card
Drop a live Pulse card for Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/themeisle-companion" width="480" height="300" style="border:0" loading="lazy" title="Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More — Plugin Pulse"></iframe> Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More: 100K+ active installs, 4.8★ (317 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/themeisle-companion