
Custom Preloader Security & Risk Analysis
wordpress.org/plugins/custom-preloaderThis Plugin it more for the Beauty of your Website! It's hiding your front page until your objects set in their positions! Custom Preloader has A …
Is Custom Preloader Safe to Use in 2026?
Generally Safe
Score 85/100Custom Preloader has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-preloader" v2.0 plugin exhibits a mixed security posture. On the positive side, there are no reported vulnerabilities in its history, no known CVEs, and the static analysis shows no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests. The absence of a large attack surface with numerous entry points is also a positive indicator.
However, a significant concern arises from the output escaping. With 100% of its 51 outputs not being properly escaped, this plugin presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is processed and then displayed by the plugin without proper sanitization or escaping is a potential vector for malicious script injection. The lack of nonce checks and the single capability check, while not inherently bad, do not mitigate the XSS risk. The taint analysis showing zero flows is likely a consequence of the limited entry points, but it does not negate the risk posed by unescaped output.
In conclusion, while the plugin has a clean vulnerability history and a seemingly small attack surface, the complete lack of output escaping is a critical flaw that overshadows its strengths. Users of this plugin should be aware of the substantial XSS risk. The absence of any recorded vulnerabilities in the past is good, but it does not guarantee future security, especially with such a fundamental security practice neglected.
Key Concerns
- All output is unescaped, high XSS risk
Custom Preloader Security Vulnerabilities
Custom Preloader Code Analysis
Output Escaping
Custom Preloader Attack Surface
WordPress Hooks 7
Maintenance & Trust
Custom Preloader Maintenance & Trust
Maintenance Signals
Community Trust
Custom Preloader Alternatives
LoftLoader
loftloader
An easy to use plugin to add an animated preloader to your website with fully customisations.
Piotnet Addons For Elementor
piotnet-addons-for-elementor
Piotnet Addons For Elementor (PAFE) adds many new features for Elementor
Favicon Rotator
favicon-rotator
Easily set site favicon and even rotate through multiple icons
Unique Headers
unique-headers
Adds the ability to use unique custom header images on individual pages, posts or categories or tags.
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Custom Preloader Developer Profile
2 plugins · 190 total installs
How We Detect Custom Preloader
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-preloader/css/style.cssHTML / DOM Fingerprints
custom_preloaderid="custom_preloader"