Darklio – AI-Powered Dark Mode Plugin for WordPress Security & Risk Analysis

wordpress.org/plugins/darklio

WordPress Dark Mode plugin to ready your site for the night. Multiple floating switches to choose between night mode and normal mode.

0 active installs v1.0.0 PHP 7.0+ WP 5.0+ Updated Mar 14, 2026
darkdark-modedark-themenight-modewordpress-dark-mode
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Darklio – AI-Powered Dark Mode Plugin for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Darklio – AI-Powered Dark Mode Plugin for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The darklio plugin v1.0.0 demonstrates a generally good security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, and file operations is a strong positive indicator. Furthermore, the fact that all REST API routes include permission callbacks and there are no unprotected entry points suggests an effort to restrict unauthorized access.

However, there are a few areas that warrant attention. The presence of external HTTP requests, while not inherently dangerous, introduces a potential attack vector if not handled securely. The 100% proper escaping of SQL queries is excellent, but the 83% output escaping rate indicates that some outputs are not being properly sanitized, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved. The lack of nonce checks on AJAX handlers is a significant concern, as it leaves these handlers vulnerable to cross-site request forgery (CSRF) attacks.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive sign, suggesting the developers are either proactive in security or the plugin hasn't been extensively targeted or scrutinized for vulnerabilities. However, the lack of historical data also means we cannot infer patterns of past security issues. In conclusion, while darklio has several strengths, particularly in its handling of database queries and entry point authentication, the missing nonce checks on AJAX handlers and less than perfect output escaping are the primary security concerns that need to be addressed.

Key Concerns

  • Missing nonce checks on AJAX handlers
  • Some output not properly escaped
  • External HTTP requests present
Vulnerabilities
None known

Darklio – AI-Powered Dark Mode Plugin for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Darklio – AI-Powered Dark Mode Plugin for WordPress Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Darklio – AI-Powered Dark Mode Plugin for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
20 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

83% escaped24 total outputs
Attack Surface

Darklio – AI-Powered Dark Mode Plugin for WordPress Attack Surface

Entry Points3
Unprotected0

REST API Routes 2

GET/wp-json/darklio/settingsincludes\admin\class-rest.php:13
PUT/wp-json/darklio/settingsincludes\admin\class-rest.php:23

Shortcodes 1

[darklio] includes\classes\class-shortcode.php:9
WordPress Hooks 11
actiondarklio_pro_check_initdarklio.php:57
actionadmin_enqueue_scriptsincludes\admin\class-assets.php:12
actionrest_api_initincludes\class-processor.php:33
actionwp_enqueue_scriptsincludes\classes\class-assets.php:13
actioninitincludes\modules\gutenberg\class-block.php:12
actionadmin_menuusers\admin\main.php:9
actionadmin_footerusers\admin\main.php:11
actionwp_enqueue_scriptsusers\frontend\main.php:11
actionwp_footerusers\frontend\main.php:13
actionlogin_footerusers\frontend\main.php:14
actionregister_footerusers\frontend\main.php:15
Maintenance & Trust

Darklio – AI-Powered Dark Mode Plugin for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version7.0
Downloads220

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Darklio – AI-Powered Dark Mode Plugin for WordPress Developer Profile

Darklio - Dark Mode Plugin for WordPress

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Darklio – AI-Powered Dark Mode Plugin for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/darklio/assets/css/admin.css/wp-content/plugins/darklio/assets/js/admin.js/wp-content/plugins/darklio/assets/css/client.css/wp-content/plugins/darklio/assets/js/client.js
Version Parameters
darklio/assets/css/admin.css?ver=darklio/assets/js/admin.js?ver=darklio/assets/css/client.css?ver=darklio/assets/js/client.js?ver=

HTML / DOM Fingerprints

JS Globals
darklio_admin_jsondarklio_json
REST Endpoints
/wp-json/darklio
FAQ

Frequently Asked Questions about Darklio – AI-Powered Dark Mode Plugin for WordPress