
CSS JS Files Security & Risk Analysis
wordpress.org/plugins/css-js-filesSelect files CSS/JS and/or write CSS/JS rules to any single page or post or globally
Is CSS JS Files Safe to Use in 2026?
Generally Safe
Score 99/100CSS JS Files has a strong security track record. Known vulnerabilities have been patched promptly.
The "css-js-files" plugin v1.5.6 presents a mixed security profile. On the positive side, the static analysis reveals no exploitable attack surface in terms of AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, the plugin demonstrates good practices with 100% of its SQL queries utilizing prepared statements and having at least one nonce check and four capability checks. However, a significant concern arises from the output escaping, with only 25% of 20 total outputs being properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before outputting to the browser. The file operations, while present, are not explicitly flagged as a risk in the taint analysis, which shows no unsanitized paths.
The vulnerability history of this plugin is a notable point of concern. While there are no currently unpatched vulnerabilities, the presence of one past CVE, specifically related to 'Improper Limitation of a Pathname to a Restricted Directory' (Path Traversal), suggests a history of critical security flaws. Although this specific vulnerability is patched, it indicates a tendency for the plugin to have had historically serious security weaknesses. The fact that the last vulnerability was very recent (September 2024) also warrants attention, suggesting that ongoing security diligence is crucial.
In conclusion, the plugin has strengths in its limited attack surface and secure SQL handling. However, the poor output escaping and the history of a serious vulnerability like path traversal, even if patched, represent significant weaknesses. The recent nature of the last vulnerability further amplifies these concerns, suggesting that while the current version might be free of known critical issues, a cautious approach is recommended due to its past security incidents and remaining code concerns.
Key Concerns
- 25% output escaping for 20 outputs
- History of 1 medium severity vulnerability
CSS JS Files Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CSS JS Files <= 1.5.0 - Authenticated (Admin+) Arbitrary File Read
CSS JS Files Code Analysis
Output Escaping
Data Flow Analysis
CSS JS Files Attack Surface
WordPress Hooks 10
Maintenance & Trust
CSS JS Files Maintenance & Trust
Maintenance Signals
Community Trust
CSS JS Files Alternatives
CSS File Selector
css-file-selector
Select files CSS and/or write CSS rules to any single page or post
Post/Page Specific Custom Code
postpage-specific-custom-css
Add custom CSS to posts, pages, or WooCommerce products, with optional archive support. Includes a dedicated editor box.
Super Simple Custom CSS
super-simple-custom-css
Super Simple Custom CSS wordpress plugin is used for adding custom styling to all post, all page,specific post,specific page or sitewide.
Custom CSS for pages
custom-css-for-pages
Create custom css for pages.
Instant CSS
instant-css
Write your styles beautifully with the power of Visual Studio Code
CSS JS Files Developer Profile
11 plugins · 390 total installs
How We Detect CSS JS Files
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/css-js-files/css-js-files.phpcss-js-files/css-js-files.php?ver=HTML / DOM Fingerprints
css-js-files-textcss-js-files-text-fullname="css_js_files_css_links"name="css_js_files_css_files[]"name="css_js_files_css_rules"name="css_js_files_css_admin"name="css_js_files_js_links"name="css_js_files_js_files[]"+7 more