
Devpri Custom Code Security & Risk Analysis
wordpress.org/plugins/devpri-custom-codeA simple plugin to display HTML/CSS/JS custom code.
Is Devpri Custom Code Safe to Use in 2026?
Generally Safe
Score 85/100Devpri Custom Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The devpri-custom-code plugin, version 1.0.0, demonstrates a strong security posture based on the provided static analysis. The plugin has no identified attack surface through common WordPress entry points like AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code analysis reveals a clean bill of health with no dangerous functions, no direct SQL queries (all are prepared statements), no file operations, and no external HTTP requests. The presence of a nonce check is a positive indicator of security awareness.
However, a significant concern arises from the output escaping, where only 53% of the 15 total outputs are properly escaped. This leaves a substantial portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if the data being outputted is not inherently safe. While the plugin has no known vulnerability history or reported CVEs, this can be attributed to its minimal feature set and lack of direct interaction points. The absence of capability checks is also a weakness, though its impact is mitigated by the lack of any entry points that would require them.
In conclusion, while the plugin excels in minimizing its attack surface and avoiding common code vulnerabilities, the incomplete output escaping presents a real and exploitable risk. The lack of a vulnerability history is a positive sign but doesn't negate the current code-level concerns. Developers should prioritize addressing the output escaping issue to improve the overall security of the plugin.
Key Concerns
- Incomplete output escaping
- Missing capability checks on entry points
Devpri Custom Code Security Vulnerabilities
Devpri Custom Code Code Analysis
Output Escaping
Data Flow Analysis
Devpri Custom Code Attack Surface
WordPress Hooks 6
Maintenance & Trust
Devpri Custom Code Maintenance & Trust
Maintenance Signals
Community Trust
Devpri Custom Code Alternatives
Custom CSS
custom-css-editor
Add custom CSS, JS, PHP, tracking code. Very easy to use!
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript
add-custom-codes
Add custom codes to your wordpress site. A completely free plugin to add Custom PHP functions, HTML, CSS, Javascript, any other codes to your website.
CM Header and Footer – Add custom scripts and styles to your header and footer with ease
cm-header-footer-script-loader
Add custom CSS and JavaScript to headers and footers on your site with the header and footer plugin for enhanced control and design.
Advanced Addons – Animation and Custom CSS for Gutenberg and Elementor
advanced-animation
Add advanced animation controls and custom CSS capabilities to Gutenberg blocks and Elementor widgets.
Devpri Custom Code Developer Profile
5 plugins · 60 total installs
How We Detect Devpri Custom Code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/devpri-custom-code/assets/css/devpri-custom-code-admin.css/wp-content/plugins/devpri-custom-code/assets/js/dcc-post.js/wp-content/plugins/devpri-custom-code/assets/js/dcc-post-editor.jsdevpri-custom-code-admin.css?ver=dcc-post.js?ver=dcc-post-editor.js?ver=