Dominant Color Security & Risk Analysis

wordpress.org/plugins/dominant-color

A WordPress plugin to automatically save the dominant color and a color palette for an attachment image into post_meta. Requires: PHP >= 7.

300 active installs v2.2.0 PHP 7.2+ WP 5.4+ Updated Apr 16, 2024
colorcolourdominancedominantimage
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Dominant Color Safe to Use in 2026?

Generally Safe

Score 92/100

Dominant Color has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "dominant-color" v2.2.0 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The static analysis reveals no identifiable attack surface, dangerous functions, unescaped output, or file operations. Crucially, all SQL queries utilize prepared statements, and there are no external HTTP requests or file operations that could be exploited. The absence of any identified taint flows further reinforces the impression of a well-secured codebase, with no unsanitized data paths leading to critical or high-severity issues. The plugin also boasts a clean vulnerability history, with zero recorded CVEs, indicating a history of secure development and maintenance. This comprehensive lack of identified vulnerabilities and potential attack vectors suggests a highly secure plugin. However, it's important to note that the analysis did not reveal any capability checks or nonce checks, which, while not directly leading to identified risks in this specific version, are standard security practices that contribute to defense-in-depth. Overall, the plugin demonstrates excellent security by design.

Vulnerabilities
None known

Dominant Color Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Dominant Color Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Dominant Color Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptsdominant-color.php:15
actionadd_attachmentdominant-color.php:25
filterattachment_fields_to_editdominant-color.php:63
filterattachment_fields_to_savedominant-color.php:111
actionplugins_loadeddominant-color.php:172
Maintenance & Trust

Dominant Color Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 16, 2024
PHP min version7.2
Downloads8K

Community Trust

Rating96/100
Number of ratings5
Active installs300
Developer Profile

Dominant Color Developer Profile

Liam Gladdy

3 plugins · 330 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dominant Color

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dominant-color/assets/dominant_colour_admin.css/wp-content/plugins/dominant-color/assets/dominant_colour_admin.js
Script Paths
/wp-content/plugins/dominant-color/assets/dominant_colour_admin.js
Version Parameters
dominant-color-js?ver=2.0

HTML / DOM Fingerprints

CSS Classes
dominant-colour-squareselecteddominantColourHoldertrigger-rebuild
Data Attributes
data-dominance-rebuilddata-coldominant-overridedominant-color
JS Globals
attachDominantColor
FAQ

Frequently Asked Questions about Dominant Color