
Easy Custom Code (LESS/CSS/JS) – Live Editing Security & Risk Analysis
wordpress.org/plugins/easy-custom-codeEasy Custom Code plugin lets you easily add custom LESS, CSS, and JavaScript code, along with external stylesheets and scripts, directly into your Wor …
Is Easy Custom Code (LESS/CSS/JS) – Live Editing Safe to Use in 2026?
Generally Safe
Score 91/100Easy Custom Code (LESS/CSS/JS) – Live Editing has a strong security track record. Known vulnerabilities have been patched promptly.
The 'easy-custom-code' v1.1.2 plugin exhibits a generally positive security posture based on the static analysis, with no identified critical or high severity taint flows and a strong adherence to prepared statements for SQL queries. The high percentage of properly escaped output is also a good indicator of defensive coding practices. However, the complete absence of nonce checks and capability checks across all entry points, coupled with a recorded medium severity vulnerability in its history, presents notable concerns. The plugin's attack surface is currently minimal, which is beneficial, but the lack of fundamental security checks like nonces leaves it susceptible to potential attacks if new entry points are introduced or existing ones are exploited without proper authentication and authorization mechanisms in place. The historical vulnerability, categorized as Cross-site Scripting, and its recent occurrence highlight a recurring area that requires vigilant attention and robust preventative measures.
While the current static analysis shows a clean bill of health regarding specific code vulnerabilities, the lack of authentication and authorization checks on any potential entry points is a significant weakness. This means that any future addition of features, even seemingly innocuous ones, could inadvertently introduce severe security flaws. The plugin's history of a medium severity XSS vulnerability, even if patched, suggests that developers should maintain a heightened awareness of input sanitization and output escaping, particularly when dealing with user-supplied data. The plugin's strengths lie in its clean SQL handling and good output escaping, but these are overshadowed by the fundamental gaps in security controls.
Key Concerns
- No nonce checks present
- No capability checks present
- 1 medium severity vulnerability in history
- 10% of outputs not properly escaped
Easy Custom Code (LESS/CSS/JS) – Live Editing Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Easy Custom Code (LESS/CSS/JS) – Live editing <= 1.0.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
Easy Custom Code (LESS/CSS/JS) – Live Editing Code Analysis
Output Escaping
Easy Custom Code (LESS/CSS/JS) – Live Editing Attack Surface
WordPress Hooks 19
Maintenance & Trust
Easy Custom Code (LESS/CSS/JS) – Live Editing Maintenance & Trust
Maintenance Signals
Community Trust
Easy Custom Code (LESS/CSS/JS) – Live Editing Alternatives
Better WordPress Minify
bwp-minify
Allows you to combine and minify your CSS and JS files to improve page load time.
WP Minify Fix
wp-minify-fix
[Fixed] This plugin uses the Minify engine to combine and compress JS and CSS files to improve page load time.
Insert Code by Angie Makes
wpc-insert-code
Easily insert HTML, Javascript, CSS, into the head and footer areas of your site.
Custom CSS/JS
wp-custom-cssjs
WP Custom CSS JS plugin allows you to add any HTML, CSS, Javascript, jQuery or Tracking Pixel easily on your wordpress site right from your dashboard.
Custom CSS, JS & PHP
custom-css
Just another custom CSS, JavaScript & PHP tool for WordPress.
Easy Custom Code (LESS/CSS/JS) – Live Editing Developer Profile
4 plugins · 30K total installs
How We Detect Easy Custom Code (LESS/CSS/JS) – Live Editing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-custom-code/admin/css/admin.min.css/wp-content/plugins/easy-custom-code/admin/js/admin.min.jseasy-custom-code/admin/css/admin.min.css?ver=easy-custom-code/admin/js/admin.min.js?ver=HTML / DOM Fingerprints
Easy Custom Code (LESS/CSS/JS) - Live editing for WordPress - v1.1.2 (free version) Author: Web357 Copyright © 2014-2025 Web357. All rights reserved. License: GNU/GPLv3, http://www.gnu.org/licenses/gpl-3.0.html +4 more