
Simple Custom CSS and JS Security & Risk Analysis
wordpress.org/plugins/custom-css-jsEasily add Custom CSS or JS to your website with an awesome editor.
Is Simple Custom CSS and JS Safe to Use in 2026?
Generally Safe
Score 100/100Simple Custom CSS and JS has a strong security track record. Known vulnerabilities have been patched promptly.
The "custom-css-js" plugin, version 3.52, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks on its entry points, which are limited to a single AJAX handler. It also avoids external HTTP requests and bundled libraries. However, several concerns warrant attention. The presence of the `unserialize` function is a significant risk, as it can lead to remote code execution if untrusted data is passed to it. Furthermore, a substantial percentage of output is not properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis revealed multiple flows with unsanitized paths, suggesting potential for data manipulation or injection, although no critical or high-severity issues were flagged in this specific analysis. The plugin's vulnerability history, though dated with its last known medium severity XSS vulnerability in 2017, indicates a past susceptibility to XSS. The absence of any recently patched vulnerabilities is encouraging, but the historical pattern of XSS and the current code signals of insufficient output escaping are weaknesses that could be exploited.
Key Concerns
- Dangerous function unserialize detected
- High percentage of unescaped output detected
- Taint analysis shows unsanitized paths
- Historical medium severity XSS vulnerability
Simple Custom CSS and JS Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Custom CSS and JS <= 3.3 - Cross-Site Scripting
Simple Custom CSS and JS Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple Custom CSS and JS Attack Surface
AJAX Handlers 1
WordPress Hooks 26
Maintenance & Trust
Simple Custom CSS and JS Maintenance & Trust
Maintenance Signals
Community Trust
Simple Custom CSS and JS Alternatives
Custom CSS
custom-css-editor
Add custom CSS, JS, PHP, tracking code. Very easy to use!
Live Custom CSS JS Code Editor
live-css-js-code-editor
Live Custom CSS JS Code Editor allows you to easily add custom CSS, JavaScript, Header, Footer Code to your site, straight from your WordPress Customi …
Custom JS
custom-js
Custom JS is easy to use. Custom JS WordPress plugin allows you to Custom JS fields in your theme - include js in head or footer.
ICustomizer
icustomizer
Personnalisation de votre administration et de votre site web
WP Smart Content
wp-smart-content
Easily inject HTML, CSS, JS, styles, scripts & tracking code via hooks / shortcodes with safe mode, scheduling, revisioning & geotargeting.
Simple Custom CSS and JS Developer Profile
5 plugins · 729K total installs
How We Detect Simple Custom CSS and JS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-css-js/upload/HTML / DOM Fingerprints
<!-- start Simple Custom CSS and JS --><!-- end Simple Custom CSS and JS -->data-ccj-id