
Code Block ScratchPad Security & Risk Analysis
wordpress.org/plugins/acb-scratchpadA simple scratchpad/testbed for testing, and installing small additions to, pre-existing PHP/JS/CSS code for wordpress websites and add-ins.
Is Code Block ScratchPad Safe to Use in 2026?
Generally Safe
Score 85/100Code Block ScratchPad has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "acb-scratchpad" plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. The complete absence of an attack surface (AJAX handlers, REST API routes, shortcodes, cron events) significantly reduces the plugin's exposure to external attacks. Furthermore, the code's adherence to secure coding practices is evidenced by 100% of SQL queries using prepared statements and a capability check present. The lack of dangerous functions, file operations, and external HTTP requests also contributes positively to its security. However, a notable area for improvement is output escaping, where only 71% of outputs are properly escaped, leaving a potential for cross-site scripting (XSS) vulnerabilities if the unescaped outputs handle user-supplied data without proper sanitization or further contextual escaping. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of its current security. Overall, "acb-scratchpad" appears to be a well-written and secure plugin, with the primary area of caution being the unescaped output. If the unescaped outputs do not process user-controlled data, this concern is minimal, but it warrants further investigation during a dynamic analysis.
Key Concerns
- 71% output escaping is not ideal
Code Block ScratchPad Security Vulnerabilities
Code Block ScratchPad Release Timeline
Code Block ScratchPad Code Analysis
Output Escaping
Code Block ScratchPad Attack Surface
WordPress Hooks 5
Maintenance & Trust
Code Block ScratchPad Maintenance & Trust
Maintenance Signals
Community Trust
Code Block ScratchPad Alternatives
Microplugins
microplugins
Añade funcionalidad al sitio mediante código desde la administración.
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager
insert-headers-and-footers
Easily add code snippets in WordPress. Insert header & footer scripts, add PHP code snippets with conditional logic, insert ads pixel code, and more.
Code Snippets
code-snippets
An easy, clean and simple way to enhance your site with code snippets.
Header Footer Code Manager
header-footer-code-manager
Easily add tracking code snippets, conversion pixels, or other scripts required by third party services for analytics, marketing, or chat features.
Insert PHP Code Snippet
insert-php-code-snippet
Add PHP code to your pages and posts easily using shortcodes.
Code Block ScratchPad Developer Profile
1 plugin · 0 total installs
How We Detect Code Block ScratchPad
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acb-scratchpad/admin/acb_sp_admin_scripts.js/wp-content/plugins/acb-scratchpad/admin/acb_sp_admin_styles.css/wp-content/plugins/acb-scratchpad/admin/acb_sp_admin_scripts.jsacb-scratchpad/admin/acb_sp_admin_scripts.js?ver=acb-scratchpad/admin/acb_sp_admin_styles.css?ver=HTML / DOM Fingerprints
acb_sp_fieldacb_hiddenacb_sp_submit_button_typeacb_sp_js_resultPDF ----------------Javascript ----------------CSS ----------------acb_field_typeacb_mime_typeacb_scrapthpad_var