
Confetti Security & Risk Analysis
wordpress.org/plugins/confettiAdd some fun and excitement to your site with confetti effects on any page of your WordPress site. Premium version integrates automatically with popul …
Is Confetti Safe to Use in 2026?
Generally Safe
Score 100/100Confetti has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "confetti" plugin v1.3.8.1 exhibits a generally good security posture with several strengths. The absence of known CVEs and a lack of critical or high severity taint flows are positive indicators. The code also demonstrates good practices with 100% of SQL queries using prepared statements and a high rate of output escaping (78%). The plugin also includes nonce checks, which is a positive security measure.
However, there are notable concerns. The presence of one unprotected AJAX handler represents a significant entry point that could be exploited if it handles user-supplied data without proper validation or authorization. While the static analysis found no critical taint flows, the unprotected AJAX handler is a prime candidate for such issues if it interacts with sensitive data or functionality. The lack of capability checks on this entry point further exacerbates the risk. A more comprehensive security audit would be beneficial to ensure all AJAX handlers are properly secured.
Overall, while the plugin has a clean vulnerability history and good code practices in many areas, the unprotected AJAX handler introduces a tangible risk. This single vulnerability, if it processes user input without sufficient sanitization or authorization, could lead to unauthorized actions or data exposure. The plugin's strengths lie in its well-handled SQL and output escaping, but its weakness lies in a single, potentially exploitable, entry point.
Key Concerns
- Unprotected AJAX handler present
- Missing capability checks on AJAX handler
- Some unescaped output present
Confetti Security Vulnerabilities
Confetti Code Analysis
Output Escaping
Data Flow Analysis
Confetti Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
Confetti Maintenance & Trust
Maintenance Signals
Community Trust
Confetti Alternatives
Successful Redirection for Contact Form
cf7-redirection
A simple add-on for Forms that adds a redirect option after form sent successfully.
Loading Page with Loading Screen
loading-page
Loading Page with Loading Screen plugin performs a pre-loading of images on your website and displays a loading progress screen with percentage of com …
View Transitions
view-transitions
Adds smooth transitions between navigations to your WordPress site.
Fast Smooth Scroll
fast-smooth-scroll
This lightweight plugin enhances user experience by enabling smooth scrolling for anchor links without the need for jQuery or other dependencies.
Confetti Fall Animation
confetti-fall-animation
Confetti fall animation plugin for WordPress. Add a delightful falling confetti animation to your website for celebrations and special events.
Confetti Developer Profile
5 plugins · 4K total installs
How We Detect Confetti
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/confetti/assets/css/admin.css/wp-content/plugins/confetti/assets/images/confetti-logo.svg/wp-content/plugins/confetti/assets/js/confetti.min.jsconfetti-admin?ver=HTML / DOM Fingerprints
wps-confetti-samplewps-headerwps-logowps-header-link--documentationwps-header-link--reviewwps-header-link--feedbackwps-header-link--upgradewps-options-menu+2 moredata-stylewps_run_confettiWPS_CONFETTI_VERSIONWPS_CONFETTI_PLUGIN_URL[confetti]