
Code View Security & Risk Analysis
wordpress.org/plugins/code-viewEasily use highlightjs and line-numbers to syntax-highlighted sample code on your blog posts
Is Code View Safe to Use in 2026?
Generally Safe
Score 85/100Code View has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "code-view" plugin v0.0.5 exhibits a generally positive security posture, adhering to several good practices. Notably, there are no recorded vulnerabilities (CVEs) or critical findings from taint analysis, suggesting a lack of exploitable flaws based on historical data and code scanning. The absence of dangerous functions, file operations, and external HTTP requests is also a strength.
However, a significant concern arises from the complete lack of output escaping across all identified outputs. This means that any data displayed to users, especially if it originates from user input or external sources, is susceptible to cross-site scripting (XSS) attacks. Furthermore, the plugin lacks nonce and capability checks for its entry points, including shortcodes. While the attack surface is small (two shortcodes) and there are no unprotected AJAX or REST API endpoints, the absence of these essential security measures on the shortcodes themselves could allow for unauthorized execution or manipulation if their functionality is sensitive or relies on authenticated user actions.
In conclusion, while the plugin benefits from a clean vulnerability history and avoidance of several high-risk code patterns, the critical deficiency in output escaping and the missing authorization checks on shortcodes present exploitable weaknesses. These issues require immediate attention to mitigate potential XSS and privilege escalation risks.
Key Concerns
- Output escaping is missing on all outputs
- Missing capability checks on shortcodes
- Missing nonce checks on shortcodes
Code View Security Vulnerabilities
Code View Release Timeline
Code View Code Analysis
Output Escaping
Code View Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
Code View Maintenance & Trust
Maintenance Signals
Community Trust
Code View Alternatives
SyntaxHighlighter2
syntaxhighlighter2
Easily post source code such as PHP or HTML and display it in a styled box.
SyntaxHighlighter Evolved: ABAP Brush
syntaxhighlighter-evolved-abap-brush
This is a Advanced Business Application Programming (ABAP) brush for the "SyntaxHighlighter Evolved" plugin.
SyntaxHighlighter Evolved
syntaxhighlighter
Easily post syntax-highlighted code to your site without having to modify the code at all. As seen on WordPress.com.
Code Widget
code-widget
Code widget help to add Short Code, PHP Code, HTML, and Simple Text in widget.
Validated
validated
This plugin will allow you to check your pages/posts HTML against the W3C Validator.
Code View Developer Profile
1 plugin · 10 total installs
How We Detect Code View
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/code-view/assets/highlight/styles/default.css/wp-content/plugins/code-view/assets/css/code-view.css/wp-content/plugins/code-view/assets/highlight/styles/atom-one-light.css/wp-content/plugins/code-view/assets/highlight/highlight.pack.js/wp-content/plugins/code-view/assets/js/line-numbers.min.js/wp-content/plugins/code-view/assets/js/register.js/wp-content/plugins/code-view/assets/highlight/highlight.pack.js/wp-content/plugins/code-view/assets/js/line-numbers.min.js/wp-content/plugins/code-view/assets/js/register.jscode-view/style.css?ver=code-view/script.js?ver=HTML / DOM Fingerprints
[cv][/cv]