Dark Mode For WP [GWE] Security & Risk Analysis

wordpress.org/plugins/dark-mode-for-wp

Use 'Dark Mode For WP' plugin to create an amazing dark version for your WordPress website. Dark Mode For WP works automatically without goi …

10 active installs v1.0.3 PHP 7.0+ WP 4.7+ Updated Sep 10, 2024
dark-modedark-themenight-modewordpress-dark-modewp-dark-mode
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dark Mode For WP [GWE] Safe to Use in 2026?

Generally Safe

Score 92/100

Dark Mode For WP [GWE] has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The security posture of the 'dark-mode-for-wp' plugin v1.0.3 appears to be quite strong based on the static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, the comprehensive use of prepared statements for SQL queries and the high percentage of properly escaped outputs suggest good development practices in preventing common injection vulnerabilities and XSS. The lack of reported vulnerabilities, including CVEs, in its history further reinforces this positive assessment.

However, there are notable areas for concern. The complete lack of nonce checks and capability checks across all identified entry points (even though the attack surface is currently reported as zero) is a significant weakness. If any entry points were to be introduced or become accessible in the future, they would be entirely unprotected against CSRF and privilege escalation attacks. The zero taint analysis flows, while positive, could also be a consequence of the limited attack surface analyzed, and doesn't guarantee absolute safety if more complex or hidden data flows exist.

In conclusion, while the plugin demonstrates excellent adherence to secure coding practices regarding data handling and output sanitization, the absence of robust access control mechanisms (nonces and capability checks) on its entry points represents a critical gap in its security. This is the primary area of risk, as it leaves the plugin vulnerable to common web attack vectors should its attack surface expand or be exploited.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • Unescaped output (15% of outputs)
Vulnerabilities
None known

Dark Mode For WP [GWE] Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Dark Mode For WP [GWE] Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped20 total outputs
Attack Surface

Dark Mode For WP [GWE] Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadeddark-mode-for-wp.php:62
actionwp_enqueue_scriptsdark-mode-for-wp.php:63
actionadmin_enqueue_scriptsdark-mode-for-wp.php:64
actionwp_footerdark-mode-for-wp.php:161
actionadmin_menudark-mode-for-wp.php:169
actionadmin_initdark-mode-for-wp.php:170
actionadmin_initdark-mode-for-wp.php:171
Maintenance & Trust

Dark Mode For WP [GWE] Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 10, 2024
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Dark Mode For WP [GWE] Developer Profile

Mukul Hossain

4 plugins · 150 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dark Mode For WP [GWE]

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dark-mode-for-wp/assets/admin/css/admin.css/wp-content/plugins/dark-mode-for-wp/dmfw-color-picker-script.js/wp-content/plugins/dark-mode-for-wp/assets/public/css/dmfwmain.css/wp-content/plugins/dark-mode-for-wp/assets/public/css/all.min.css/wp-content/plugins/dark-mode-for-wp/assets/public/css/fontawesome.min.css/wp-content/plugins/dark-mode-for-wp/assets/public/js/dmfwmain.js
Script Paths
dmfw-color-picker-script.js
Version Parameters
dmfw-admin-cssdmfw-color-picker-jsdmfw-main-cssdmfw-all-fontawesomedmfw-min-fontawesomedmfw-main-js

HTML / DOM Fingerprints

CSS Classes
dmfw-theme-btndmfw-dark-modedmfw_form
Data Attributes
data-dmfw-toggle
FAQ

Frequently Asked Questions about Dark Mode For WP [GWE]