
Automatic NBSP Security & Risk Analysis
wordpress.org/plugins/automatic-nbspAutomatically adds a non-breaking space ( ) in the content.
Is Automatic NBSP Safe to Use in 2026?
Generally Safe
Score 85/100Automatic NBSP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "automatic-nbsp" plugin v1.5.4 exhibits a generally strong security posture based on the provided static analysis. There are no identified attack vectors such as AJAX handlers, REST API routes, or shortcodes, which significantly reduces the potential for external exploitation. Furthermore, the plugin demonstrates good practices by not using dangerous functions, performing all SQL queries with prepared statements, and not making external HTTP requests.
However, a notable concern arises from the output escaping. With only 35% of the 17 identified outputs being properly escaped, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that potentially malicious script content could be injected into the website and executed in the user's browser. The absence of nonce checks and capability checks on any potential entry points, while currently a moot point due to the lack of entry points, would be a critical oversight if any were introduced.
The plugin's vulnerability history is clean, with no recorded CVEs. This suggests a history of responsible development and timely patching, which is a positive indicator. However, the lack of historical vulnerabilities can sometimes mask underlying coding practices that might lead to issues when new features are added or the WordPress environment changes. The primary weakness identified is the insufficient output escaping, which should be addressed as a priority.
Key Concerns
- Insufficient output escaping
Automatic NBSP Security Vulnerabilities
Automatic NBSP Release Timeline
Automatic NBSP Code Analysis
Output Escaping
Automatic NBSP Attack Surface
WordPress Hooks 14
Maintenance & Trust
Automatic NBSP Maintenance & Trust
Maintenance Signals
Community Trust
Automatic NBSP Alternatives
Orphans
sierotki
Supports the grammar rule for orphan words at the end of a line.
Speedx Smart Line Breaks
speedx-smart-line-breaks
Speedx Smart Line Breaks is a lightweight yet powerful typography plugin for WordPress.
Fonts Plugin | Google Fonts, Adobe Fonts & Upload Fonts
olympus-google-fonts
Instantly change your entire website's typography with Google Fonts, Adobe Fonts, or custom fonts — no coding required. Live preview your changes.
Use Any Font | Custom Font Uploader
use-any-font
Upload custom fonts with custom font uploader. Auto converts to woff2 for better performance. Self-hosted, GDPR compliant, and easy custom font plugin
Easy Google Fonts
easy-google-fonts
Adds google fonts to any theme without coding and integrates with the WordPress Customizer automatically for a realtime live preview.
Automatic NBSP Developer Profile
1 plugin · 3K total installs
How We Detect Automatic NBSP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/automatic-nbsp/assets/js/admin-scripts.js/wp-content/plugins/automatic-nbsp/assets/css/admin-style.css/wp-content/plugins/automatic-nbsp/assets/js/admin-scripts.jsautomatic-nbsp/assets/js/admin-scripts.js?ver=automatic-nbsp/assets/css/admin-style.css?ver=