Code Engine – PHP Snippets, AI Functions & Automation for WordPress Security & Risk Analysis

wordpress.org/plugins/code-engine

Manage PHP & JS snippets the clean way, then turn any function into an AI tool, a workflow step, or a REST endpoint. Write once, use everywhere. 🤟

700 active installs v0.5.5 PHP 7.4+ WP 6.0+ Updated Jul 18, 2026
aiautomationcodephpsnippets
93
A · Safe
CVEs total3
Unpatched0
Last CVEJul 10, 2026
Safety Verdict

Is Code Engine – PHP Snippets, AI Functions & Automation for WordPress Safe to Use in 2026?

Generally Safe

Score 93/100

Code Engine – PHP Snippets, AI Functions & Automation for WordPress has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Jul 10, 2026Updated 1mo ago
Risk Assessment

The "code-engine" v0.4.3 plugin exhibits a mixed security posture. While it demonstrates good practices such as a low attack surface with a single shortcode entry point and generally good output escaping (86%) and prepared statement usage (67% for SQL queries), there are notable concerns. The presence of 3 instances of `preg_replace` with the `/e` modifier is a significant red flag, as this is a known vulnerability vector for arbitrary code execution. The vulnerability history, with 2 known CVEs, including a past high-severity vulnerability related to Code Injection and Cross-site Scripting, further elevates the risk. Although there are no currently unpatched CVEs and taint analysis showed no critical or high severity flows, the historical pattern suggests potential weaknesses in input sanitization and output neutralization that could be exploited.

Overall, the plugin has strengths in limiting its attack surface and implementing some security best practices. However, the identified dangerous function usage (`preg_replace(/e)`) and the historical vulnerability types warrant caution. The absence of any taint flows in the static analysis might be due to the limited scope of the analysis or the specific code paths tested, and does not fully mitigate the risk posed by the `preg_replace` usage and past vulnerabilities. Users should be aware of these potential weaknesses and ensure the plugin is kept up-to-date with any future patches.

Key Concerns

  • Dangerous function usage (preg_replace(/e))
  • History of high-severity vulnerability (Code Injection/XSS)
  • SQL queries without prepared statements
Vulnerabilities
3 published

Code Engine – PHP Snippets, AI Functions & Automation for WordPress Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

High
2
Medium
1

3 total CVEs

CVE-2025-6784high · 8.8Improper Neutralization of Special Elements used in a Command ('Command Injection')

Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution

Jul 10, 2026 Patched in 0.3.6 (1d)
CVE-2025-48169high · 8.8Improper Control of Generation of Code ('Code Injection')

Code Engine <= 0.3.3 - Authenticated (Contributor+) Remote Code Execution

Aug 7, 2025 Patched in 0.3.4 (5d)
CVE-2025-50043medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Code Engine <= 0.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 19, 2025 Patched in 0.3.3 (37d)
Version History

Code Engine – PHP Snippets, AI Functions & Automation for WordPress Release Timeline

v0.5.5Current
v0.5.4
v0.5.3
v0.5.2
v0.5.1
v0.5.0
v0.4.9
v0.4.8
v0.4.7
v0.4.6
v0.4.5
v0.4.4
v0.4.3
v0.4.2
v0.4.1
v0.4.0
v0.3.9
v0.3.8
v0.3.7
v0.3.6
Code Analysis
Analyzed Mar 16, 2026

Code Engine – PHP Snippets, AI Functions & Automation for WordPress Code Analysis

Dangerous Functions
3
Raw SQL Queries
9
18 prepared
Unescaped Output
4
24 escaped
Nonce Checks
1
Capability Checks
11
File Operations
6
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

preg_replace(/e)preg_replace( '/eclasses\core.php:300
preg_replace(/e)preg_replace( '/eclasses\core.php:406
preg_replace(/e)preg_replace( '/eclasses\core.php:408

SQL Query Safety

67% prepared27 total queries

Output Escaping

86% escaped28 total outputs
Attack Surface

Code Engine – PHP Snippets, AI Functions & Automation for WordPress Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[code-engine] classes\core.php:36
WordPress Hooks 27
actionadmin_menuclasses\admin.php:11
actionadmin_enqueue_scriptsclasses\admin.php:27
actionplugins_loadedclasses\core.php:38
actionadmin_noticesclasses\init.php:8
actionplugins_loadedclasses\load.php:4
actionwp_enqueue_scriptsclasses\load.php:200
actionadmin_enqueue_scriptsclasses\load.php:201
actioninitclasses\mcp.php:11
filtermwai_mcp_toolsclasses\mcp.php:21
filtermwai_mcp_callbackclasses\mcp.php:24
filtercron_schedulesclasses\modules\cron.php:7
actioninitclasses\modules\cron.php:8
actionrest_api_initclasses\rest.php:19
filtermwcode_allow_public_apiclasses\rest.php:183
actionadmin_noticescommon\admin.php:72
filterplugin_row_metacommon\admin.php:77
filteredd_sl_api_request_verify_sslcommon\admin.php:78
actioninitcommon\admin.php:96
actionadmin_menucommon\admin.php:153
filteradmin_footer_textcommon\admin.php:158
actionadmin_footercommon\admin.php:218
actionadmin_headcommon\admin.php:456
actionadmin_noticescommon\news.php:43
filtersafe_style_csscommon\news.php:44
actionadmin_noticescommon\ratings.php:33
filtersafe_style_csscommon\ratings.php:34
actionrest_api_initcommon\rest.php:14
Maintenance & Trust

Code Engine – PHP Snippets, AI Functions & Automation for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJul 18, 2026
PHP min version7.4
Downloads19K

Community Trust

Rating100/100
Number of ratings9
Active installs700
Developer Profile

Code Engine – PHP Snippets, AI Functions & Automation for WordPress Developer Profile

Jordy Meow

30 plugins · 361K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
328 days
View full developer profile
Detection Fingerprints

How We Detect Code Engine – PHP Snippets, AI Functions & Automation for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/code-engine/app/index.js/wp-content/plugins/code-engine/app/vendor.js
Script Paths
https://fonts.googleapis.com/css2?family=Lato:wght@100;300;400;700;900&display=swap
Version Parameters
code-engine/app/index.js?ver=code-engine/app/vendor.js?ver=

HTML / DOM Fingerprints

Data Attributes
mwcode-admin-settings
JS Globals
mwcode_snippet_vault
REST Endpoints
/wp-json/code-engine/v1
FAQ

Frequently Asked Questions about Code Engine – PHP Snippets, AI Functions & Automation for WordPress