Code Prettify Syntax Highlighter Security & Risk Analysis

wordpress.org/plugins/code-prettify-syntax-highlighter

Highlighting the code in the post with JavaScript library «google-code-prettify».

10 active installs v1.0 PHP + WP 3.5+ Updated Dec 17, 2012
codecsshighlighterhtmljavascript
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Code Prettify Syntax Highlighter Safe to Use in 2026?

Generally Safe

Score 85/100

Code Prettify Syntax Highlighter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "code-prettify-syntax-highlighter" v1.0 plugin currently presents a very low security risk based on the provided static analysis and vulnerability history. The static analysis shows no identified entry points like AJAX handlers, REST API routes, or shortcodes, and importantly, no unprotected ones. Furthermore, the code signals indicate a strong adherence to secure coding practices, with all SQL queries using prepared statements and no dangerous functions, file operations, or external HTTP requests detected. The lack of any taint analysis findings further reinforces its secure state.

The vulnerability history is also clean, with zero recorded CVEs. This, combined with the static analysis findings, suggests that the plugin developers have likely followed secure development guidelines and that the plugin has not been a target or a source of known vulnerabilities to date. However, it is crucial to note that the absence of output escaping on the three identified output points is a concern, as it represents a potential vulnerability if user-supplied data were to be rendered directly. While this specific instance does not show a flow, it is a potential weakness that could be exploited if the plugin's functionality changes or expands.

In conclusion, the plugin exhibits a strong security posture due to its limited attack surface and the use of prepared statements. The clean vulnerability history is a significant positive indicator. The primary area of concern, albeit minor in this context due to the lack of identified flows, is the absence of output escaping. Continuous monitoring and code reviews, especially if the plugin is updated, are still recommended.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Code Prettify Syntax Highlighter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Code Prettify Syntax Highlighter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

Code Prettify Syntax Highlighter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_enqueue_scriptscpsh.php:15
actionadmin_initcpsh.php:16
actionthe_contentcpsh.php:26
actionthe_excerptcpsh.php:27
actioncontent_save_precpsh.php:57
Maintenance & Trust

Code Prettify Syntax Highlighter Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedDec 17, 2012
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Code Prettify Syntax Highlighter Developer Profile

TrueFalse

6 plugins · 420 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Code Prettify Syntax Highlighter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/code-prettify-syntax-highlighter/google-code-prettify/prettify.css/wp-content/plugins/code-prettify-syntax-highlighter/google-code-prettify/prettify.js/wp-content/plugins/code-prettify-syntax-highlighter/google-code-prettify/prettify.init.js
Script Paths
/wp-content/plugins/code-prettify-syntax-highlighter/google-code-prettify/prettify.js/wp-content/plugins/code-prettify-syntax-highlighter/google-code-prettify/prettify.init.js

HTML / DOM Fingerprints

CSS Classes
prettyprintlinenums
FAQ

Frequently Asked Questions about Code Prettify Syntax Highlighter