
Advanced Custom CSS Security & Risk Analysis
wordpress.org/plugins/advanced-custom-cssAdd Custom CSS to your WordPress site. Easy and Flexible.
Is Advanced Custom CSS Safe to Use in 2026?
Use With Caution
Score 63/100Advanced Custom CSS has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "advanced-custom-css" plugin, version 1.1.0, presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and having no critical or high-severity issues in its taint analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events also limits its direct attack surface. However, significant concerns arise from the low percentage of properly escaped output (17%) and the presence of a single flow with unsanitized paths identified during taint analysis. This suggests a potential for cross-site scripting (XSS) vulnerabilities where user-supplied data might not be adequately neutralized before being rendered.
The plugin's vulnerability history is a notable red flag. With one known medium-severity CVE related to Cross-site Scripting that remains unpatched, it indicates a recurring weakness in input sanitization. While the current static analysis did not flag this specific vulnerability, the past pattern strongly suggests that the underlying issues might still exist or have not been fully remediated. The fact that the last vulnerability was recorded in the future (2025-12-26) is also an anomaly that warrants attention, although it may be a data input error. Overall, while the plugin has strengths in SQL handling and a limited attack surface, the unpatched XSS vulnerability and potential for unsanitized output and paths pose a significant risk that requires immediate attention and thorough auditing.
Key Concerns
- Unpatched medium severity CVE
- Flow with unsanitized paths
- Low percentage of properly escaped output
- 1 vulnerability history entry
Advanced Custom CSS Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Advanced Custom CSS <= 1.1.0 - Reflected Cross-Site Scripting
Advanced Custom CSS Code Analysis
Output Escaping
Data Flow Analysis
Advanced Custom CSS Attack Surface
WordPress Hooks 3
Maintenance & Trust
Advanced Custom CSS Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom CSS Alternatives
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
Insert Headers And Footers
wp-headers-and-footers
Include inline javascript, stylesheets, CSS code or anything you want in Header and Footer areas of your WordPress with ease.
Simple Custom CSS Plugin
simple-custom-css
Add Custom CSS to your WordPress site without any hassles.
Simple CSS
simple-css
Add CSS to your website through an admin editor, the Customizer or a metabox for page/post specific CSS.
WP Add Custom CSS
wp-add-custom-css
Add custom css to the whole website and to specific posts and pages.
Advanced Custom CSS Developer Profile
5 plugins · 91K total installs
How We Detect Advanced Custom CSS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-custom-css/include/materialize/materialize.min.js/wp-content/plugins/advanced-custom-css/include/codemirror/codemirror.js/wp-content/plugins/advanced-custom-css/include/codemirror/css.js/wp-content/plugins/advanced-custom-css/include/codemirror/cm_init.js/wp-content/plugins/advanced-custom-css/include/codemirror/autorefresh.js/wp-content/plugins/advanced-custom-css/include/materialize/materialize.min.css/wp-content/plugins/advanced-custom-css/include/codemirror/codemirror.css/wp-content/plugins/advanced-custom-css/include/codemirror/dracula.css+1 more/wp-content/plugins/advanced-custom-css/include/materialize/materialize.min.js/wp-content/plugins/advanced-custom-css/include/codemirror/codemirror.js/wp-content/plugins/advanced-custom-css/include/codemirror/css.js/wp-content/plugins/advanced-custom-css/include/codemirror/cm_init.js/wp-content/plugins/advanced-custom-css/include/codemirror/autorefresh.jsHTML / DOM Fingerprints
/*CSS added here will be included everywhere on site. You can use this option to set global CSS rules for your website.*//*CSS added here will be included on single posts on site.*//*CSS added here will be included on single page on site.*//*CSS added by Advanced Custom CSS Plugin*/