AI Code Highlight Security & Risk Analysis

wordpress.org/plugins/ai-code-highlighter

Highlight your code using Google Code Prettify Script. Simply press the button on editor toolbar and paste your code. The plugin does all the rest.

10 active installs v1.3 PHP + WP 3.0.1+ Updated Jan 29, 2014
code-highlight
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AI Code Highlight Safe to Use in 2026?

Generally Safe

Score 85/100

AI Code Highlight has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "ai-code-highlighter" v1.3 plugin exhibits a strong security posture based on the provided static analysis. There are no identified vulnerabilities in its attack surface, such as AJAX handlers, REST API routes, or shortcodes. Furthermore, the code demonstrates good development practices with 100% of SQL queries using prepared statements and all outputs being properly escaped, indicating a low risk of common injection and cross-site scripting vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further solidifies this positive assessment.

The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a proactive approach to security by the developers or a lack of previously discovered significant flaws. The presence of capability checks, even with a small number, is a positive indicator for access control. However, the total absence of nonce checks on entry points is a notable area for potential improvement, as it could theoretically expose the plugin to CSRF attacks if any of the capability checks were bypassed or if new functionalities were added without proper nonce implementation.

In conclusion, "ai-code-highlighter" v1.3 appears to be a secure plugin with robust coding practices. The primary area for potential concern is the lack of nonce checks across its entry points, which, while not currently a demonstrated issue, represents a potential weakness that could be exploited in future scenarios. The absence of any known vulnerabilities or critical taint flows is highly encouraging.

Key Concerns

  • No nonce checks on entry points
Vulnerabilities
None known

AI Code Highlight Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AI Code Highlight Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

AI Code Highlight Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_enqueue_scriptsai-code-highliter.php:30
actionwp_enqueue_scriptsai-code-highliter.php:39
actionadmin_initai-code-highliter.php:54
filtermce_buttonsai-code-highliter.php:61
filtermce_external_pluginsai-code-highliter.php:62
Maintenance & Trust

AI Code Highlight Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJan 29, 2014
PHP min version
Downloads3K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

AI Code Highlight Developer Profile

Andrei Ionescu

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AI Code Highlight

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ai-code-highlighter/prettify/prettify.js/wp-content/plugins/ai-code-highlighter/prettify/run_prettify.js/wp-content/plugins/ai-code-highlighter/ai-code-highliter_plugin.js
Script Paths
prettify/prettify.jsprettify/run_prettify.js?autoload=true&skin=sunburstai-code-highliter_plugin.js?plugin_folder=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about AI Code Highlight