Cursor Image Lite Security & Risk Analysis

wordpress.org/plugins/cursor-image-lite

Easily replace the default mouse cursor with your own custom PNG images. A lightweight and simple custom cursor plugin for WordPress.

100 active installs v1.0.3 PHP 7.4+ WP 5.0+ Updated Dec 7, 2025
cursorcustom-cursorcustomizationpng-cursorpointer
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cursor Image Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Cursor Image Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "cursor-image-lite" v1.0.3 plugin exhibits a generally good security posture, with no recorded vulnerabilities and strong adherence to many secure coding practices. The plugin utilizes prepared statements for all SQL queries, a significant security strength. It also demonstrates a high percentage of properly escaped output and incorporates nonce and capability checks, indicating an awareness of common WordPress security pitfalls.

However, a notable concern arises from the presence of one unprotected AJAX handler. This unprotected entry point represents a potential attack vector, as it lacks authentication and authorization checks. While no critical taint flows were identified in the static analysis, the presence of an unprotected AJAX handler means that any data processed by it, if not handled with extreme care, could become vulnerable to injection attacks. The absence of a vulnerability history is positive but does not guarantee future security, especially given the identified unprotected AJAX handler.

In conclusion, the plugin's foundation is solid with good coding practices evident. The primary weakness lies in the single unprotected AJAX endpoint, which, while not indicative of immediate critical flaws based on the provided data, requires careful consideration and potential mitigation to ensure comprehensive security. Addressing this single point of entry would significantly strengthen the plugin's overall security.

Key Concerns

  • Unprotected AJAX handler found
Vulnerabilities
None known

Cursor Image Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cursor Image Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
24 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped26 total outputs
Attack Surface
1 unprotected

Cursor Image Lite Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_cursimli_dismiss_support_noticeincludes\admin.php:211
WordPress Hooks 7
actionwp_enqueue_scriptscursor-image-lite.php:64
actionadmin_menuincludes\admin.php:4
actionadmin_initincludes\admin.php:5
actionadmin_enqueue_scriptsincludes\admin.php:6
actionadmin_enqueue_scriptsincludes\admin.php:7
actionadmin_noticesincludes\admin.php:182
actionwp_enqueue_scriptsincludes\public.php:4
Maintenance & Trust

Cursor Image Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 7, 2025
PHP min version7.4
Downloads478

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Cursor Image Lite Developer Profile

Haruki

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cursor Image Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cursor-image-lite/assets/js/cursimli-cursor.js/wp-content/plugins/cursor-image-lite/assets/js/admin.js/wp-content/plugins/cursor-image-lite/assets/css/admin.css
Script Paths
/wp-content/plugins/cursor-image-lite/assets/js/cursimli-cursor.js/wp-content/plugins/cursor-image-lite/assets/js/admin.js
Version Parameters
cursor-image-lite/assets/js/cursimli-cursor.js?ver=cursor-image-lite/assets/js/admin.js?ver=cursor-image-lite/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
cursimli-wrapcursimli-tablecursimli-preview-wrap
Data Attributes
data-cursimli-cursordata-cursimli-hover
JS Globals
cursimli_admin_object
FAQ

Frequently Asked Questions about Cursor Image Lite