
Code Manager Security & Risk Analysis
wordpress.org/plugins/code-managerWrite, test and deploy PHP, JavaScript, CSS and HTML code blocks from the WordPress dashboard.
Is Code Manager Safe to Use in 2026?
Generally Safe
Score 100/100Code Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "code-manager" v1.0.45 plugin exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the plugin demonstrates good practices in its use of prepared statements for SQL queries and a reasonable rate of output escaping, the fact that all 13 identified AJAX entry points lack authentication checks is a major weakness. This opens the door for unauthorized users to trigger potentially sensitive actions or manipulate plugin functionality without proper authorization.
The static analysis also revealed three flows with unsanitized paths, with one flagged as high severity, indicating a potential for path traversal or insecure file operations if these flows are triggered by user input. The absence of known historical vulnerabilities is a positive sign, suggesting either a well-maintained codebase or a lack of prior focused security scrutiny. However, this should not overshadow the immediate risks posed by the unprotected AJAX endpoints and the identified high-severity taint flow.
In conclusion, while the "code-manager" plugin has some strengths in its database and output handling, the lack of authentication on its AJAX handlers and the presence of high-severity taint flows represent significant security risks. The plugin requires immediate attention to secure these entry points and address the identified path-related vulnerabilities to improve its overall security. The absence of historical vulnerabilities is a positive but does not mitigate the current risks.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flow (unsanitized path)
- Flows with unsanitized paths
- Low percentage of properly escaped output
Code Manager Security Vulnerabilities
Code Manager Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Code Manager Attack Surface
AJAX Handlers 13
WordPress Hooks 21
Maintenance & Trust
Code Manager Maintenance & Trust
Maintenance Signals
Community Trust
Code Manager Alternatives
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager
insert-headers-and-footers
Easily add code snippets in WordPress. Insert header & footer scripts, add PHP code snippets with conditional logic, insert ads pixel code, and more.
SiteOrigin CSS
so-css
Powerful, simple CSS editing for WordPress. Visual controls & real-time previews for effortless site customization.
Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts
insert-php
Insert PHP, JavaScript, CSS, HTML, ads, and tracking code into WordPress headers, footers, pages, and content using conditional logic, without editing …
FluentSnippets – The High-Performance file based Custom Code Snippets Plugin
easy-code-manager
Add header and footer scripts, PHP Snippets, Custom CSS /JS snippets with advanced conditional logic, and more...
Visual CSS Style Editor
yellow-pencil-visual-theme-customizer
Style your WordPress site visually. Discover the most popular front-end design plugin! Try live demo.
Code Manager Developer Profile
2 plugins · 11K total installs
How We Detect Code Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/code-manager/code-manager-config.php/wp-content/plugins/code-manager/vendor/freemius/assets/img/code-manager.png/wp-content/plugins/code-manager/includes/class-code-manager-switch.phpcode-manager/code-manager-config.php?ver=code-manager/includes/class-code-manager-switch.php?ver=HTML / DOM Fingerprints
data-cm-iddata-cm-namedata-cm-typecode_manager_fs/wp-json/code-manager/