Canvas-Nest.js Security & Risk Analysis

wordpress.org/plugins/canvas-nestjs

[正版]A wordpress plugin for canvas-nest.js | 一个很炫酷网页背景效果(canvas-nest.js)的wordpress插件。

90 active installs v1.0.1 PHP + WP 3.0.1+ Updated Jan 25, 2016
canvasgithubhtml5nestparticle
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Canvas-Nest.js Safe to Use in 2026?

Generally Safe

Score 85/100

Canvas-Nest.js has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin 'canvas-nestjs' v1.0.1 exhibits an excellent security posture based on the static analysis and vulnerability history provided. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions, no raw SQL queries, and no file operations, external HTTP requests, or taint flows. The presence of capability checks and the use of prepared statements for SQL queries are positive indicators.

However, a notable concern arises from the complete lack of output escaping. With 3 total outputs and 0% properly escaped, this presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. An attacker could potentially inject malicious scripts through user-controlled input that is then displayed without proper sanitization, impacting users of the WordPress site. The vulnerability history being entirely clear is a strong positive, suggesting a well-maintained and secure development process historically.

In conclusion, while the plugin demonstrates strong foundational security by minimizing its attack surface and adhering to secure coding practices for data handling, the complete lack of output escaping is a critical weakness that needs immediate attention. This oversight could undermine the otherwise strong security posture of the plugin.

Key Concerns

  • No output escaping
Vulnerabilities
None known

Canvas-Nest.js Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Canvas-Nest.js Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Canvas-Nest.js Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initsettings.php:10
actionadmin_menusettings.php:11
actionwp_footersettings.php:12
Maintenance & Trust

Canvas-Nest.js Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJan 25, 2016
PHP min version
Downloads11K

Community Trust

Rating80/100
Number of ratings2
Active installs90
Developer Profile

Canvas-Nest.js Developer Profile

wzwahl36

1 plugin · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Canvas-Nest.js

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
//cdn.bootcss.com/canvas-nest.js/1.0.0/canvas-nest.min.js

HTML / DOM Fingerprints

Data Attributes
colorzIndexopacitycount
FAQ

Frequently Asked Questions about Canvas-Nest.js