Distraction Free Writing mode Themes Security & Risk Analysis

wordpress.org/plugins/distraction-free-writing-mode-themes

Provides dark and light themes for for Distraction Free Writing mode. Use one of the beautiful built-in themes or write your own.

10 active installs v3.1.0 PHP + WP 3.5+ Updated Jul 26, 2015
dark-themeeditorthemes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Distraction Free Writing mode Themes Safe to Use in 2026?

Generally Safe

Score 85/100

Distraction Free Writing mode Themes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "distraction-free-writing-mode-themes" plugin version 3.1.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified direct entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are accessible to attackers. The absence of dangerous functions, direct SQL queries (all use prepared statements), file operations, and external HTTP requests further bolsters its security. Furthermore, the plugin has no known vulnerabilities in its history, which is a very positive indicator.

However, a significant concern arises from the low percentage of properly escaped output (5%). With 21 total outputs, only one is properly escaped, leaving 20 outputs potentially vulnerable to cross-site scripting (XSS) attacks if they handle user-supplied data. The lack of nonce checks on any entry points is also concerning, although the absence of entry points mitigates this risk for now. The presence of only one capability check is minimal and could be insufficient for safeguarding sensitive operations if any were present.

In conclusion, while the plugin's design minimizes its attack surface and it has a clean vulnerability history, the poor output escaping practices represent a notable risk. If any of the unescaped outputs handle user-controlled input in the future, this could lead to critical XSS vulnerabilities. The lack of nonce checks, while currently mitigated by the lack of entry points, is a weakness that should be addressed proactively if the plugin's functionality evolves to include user interaction points.

Key Concerns

  • Low output escaping (5%)
  • No nonce checks on entry points
  • Minimal capability checks
Vulnerabilities
None known

Distraction Free Writing mode Themes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Distraction Free Writing mode Themes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

5% escaped21 total outputs
Attack Surface

Distraction Free Writing mode Themes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
filtermce_cssdistraction-free-writing-mode-themes.php:29
actionadmin_print_styles-post.phpdistraction-free-writing-mode-themes.php:30
actionadmin_print_styles-post-new.phpdistraction-free-writing-mode-themes.php:31
actionadmin_menudistraction-free-writing-mode-themes.php:36
actionadmin_initdistraction-free-writing-mode-themes.php:37
actionadmin_footerdistraction-free-writing-mode-themes.php:38
actionshow_user_profiledistraction-free-writing-mode-themes.php:41
actionedit_user_profiledistraction-free-writing-mode-themes.php:42
actionshow_user_profiledistraction-free-writing-mode-themes.php:43
actionedit_user_profiledistraction-free-writing-mode-themes.php:44
actionpersonal_options_updatedistraction-free-writing-mode-themes.php:46
actionedit_user_profile_updatedistraction-free-writing-mode-themes.php:47
filterquery_varsdistraction-free-writing-mode-themes.php:50
actiontemplate_redirectdistraction-free-writing-mode-themes.php:53
Maintenance & Trust

Distraction Free Writing mode Themes Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJul 26, 2015
PHP min version
Downloads5K

Community Trust

Rating96/100
Number of ratings4
Active installs10
Developer Profile

Distraction Free Writing mode Themes Developer Profile

Stanislav Khromov

6 plugins · 6K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Distraction Free Writing mode Themes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/distraction-free-writing-mode-themes/css//wp-content/plugins/distraction-free-writing-mode-themes/lib//wp-content/plugins/distraction-free-writing-mode-themes/templates/
Script Paths
/wp-content/plugins/distraction-free-writing-mode-themes/lib/microtemplate.class.php
Version Parameters
distraction-free-writing-mode-themes/css/distraction-free-writing-mode-themes/lib/

HTML / DOM Fingerprints

CSS Classes
dfwm-post-editor
Data Attributes
data-dfwmt-editor-id
JS Globals
wp.editor.initialize
FAQ

Frequently Asked Questions about Distraction Free Writing mode Themes