Confetti Fall Animation Security & Risk Analysis

wordpress.org/plugins/confetti-fall-animation

Confetti fall animation plugin for WordPress. Add a delightful falling confetti animation to your website for celebrations and special events.

600 active installs v1.3.2 PHP + WP 6.0.1+ Updated Jan 27, 2026
animationcelebrationconfettifireworksshortcode
99
A · Safe
CVEs total2
Unpatched0
Last CVESep 30, 2024
Safety Verdict

Is Confetti Fall Animation Safe to Use in 2026?

Generally Safe

Score 99/100

Confetti Fall Animation has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Sep 30, 2024Updated 2mo ago
Risk Assessment

The plugin 'confetti-fall-animation' v1.3.2 exhibits a generally positive security posture based on the static analysis. The absence of dangerous functions, file operations, external HTTP requests, and raw SQL queries is a strong indicator of secure coding practices. Furthermore, the high percentage of properly escaped output and the presence of nonce and capability checks on entry points demonstrate a good understanding of WordPress security principles. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, further reinforces this positive assessment.

However, the vulnerability history is a significant concern. The presence of two known medium-severity Cross-Site Scripting (XSS) vulnerabilities, even if currently patched, suggests a potential for insecure input handling that could be exploited in future versions if not meticulously addressed. The fact that the last vulnerability was recent (September 30, 2024) also indicates that the development team may still be encountering security challenges. While current analysis shows no critical or high severity issues and no unsanitized taint flows, the historical pattern necessitates vigilance and a thorough review of how user-supplied data is processed by the shortcode.

In conclusion, while the current code analysis for v1.3.2 reveals a technically sound implementation with good security controls, the plugin's past vulnerability history, particularly concerning XSS, warrants a cautious approach. The strengths lie in the implemented security checks and avoidance of common dangerous practices. The primary weakness is the historical tendency to introduce XSS vulnerabilities, which, despite current patching, casts a shadow on its long-term security reliability. Continued monitoring and a rigorous security development lifecycle are recommended.

Key Concerns

  • Known medium severity CVEs historically present
  • Recent vulnerability history (2024-09-30)
  • XSS as common vulnerability type historically
Vulnerabilities
2

Confetti Fall Animation Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-47641medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Confetti Fall Animation <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 30, 2024 Patched in 1.3.1 (481d)
CVE-2024-8919medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Confetti Fall Animation <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via confetti-fall-animation Shortcode

Sep 23, 2024 Patched in 1.3.2 (487d)
Code Analysis
Analyzed Mar 16, 2026

Confetti Fall Animation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
21 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped23 total outputs
Attack Surface

Confetti Fall Animation Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[confetti-fall-animation] confetti-fall-animation.php:39
WordPress Hooks 11
actionwp_enqueue_scriptsconfetti-fall-animation.php:25
actionadmin_enqueue_scriptsconfetti-fall-animation.php:26
actionadmin_menuconfetti-fall-animation.php:28
actionadmin_initconfetti-fall-animation.php:29
actionwp_footerconfetti-fall-animation.php:31
actionadmin_noticesconfetti-fall-animation.php:32
actionadd_meta_boxesconfetti-fall-animation.php:34
actionadmin_footerconfetti-fall-animation.php:35
actionwpconfetti-fall-animation.php:37
actionwp_headinc\popupBackgroundImage.php:98
actionadmin_enqueue_scriptsinc\popupBackgroundImage.php:99
Maintenance & Trust

Confetti Fall Animation Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 27, 2026
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings2
Active installs600
Developer Profile

Confetti Fall Animation Developer Profile

Muhammad Shakeel

1 plugin · 600 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
484 days
View full developer profile
Detection Fingerprints

How We Detect Confetti Fall Animation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/confetti-fall-animation/assets/js/confetti.min.js/wp-content/plugins/confetti-fall-animation/assets/js/confetti-fall-animation.js/wp-content/plugins/confetti-fall-animation/assets/js/popup-plugin.js/wp-content/plugins/confetti-fall-animation/assets/css/popup-plugin.css
Script Paths
/wp-content/plugins/confetti-fall-animation/assets/js/confetti.min.js/wp-content/plugins/confetti-fall-animation/assets/js/confetti-fall-animation.js/wp-content/plugins/confetti-fall-animation/assets/js/popup-plugin.js
Version Parameters
confetti-fall-animation/assets/js/confetti.min.js?ver=confetti-fall-animation/assets/js/confetti-fall-animation.js?ver=confetti-fall-animation/assets/js/popup-plugin.js?ver=confetti-fall-animation/assets/css/popup-plugin.css?ver=

HTML / DOM Fingerprints

CSS Classes
confetti-popup-content
Data Attributes
id="confetti-popup"id="confetti-popup-close"id="cfa-insert-shortcode"
JS Globals
delayPopupSettings
Shortcode Output
[confetti-fall-animation]
FAQ

Frequently Asked Questions about Confetti Fall Animation