
Easy Custom Code (LESS/CSS/JS) – Live Editing Security & Risk Analysis
wordpress.org/plugins/easy-custom-codeEasy Custom Code plugin lets you easily add custom LESS, CSS, and JavaScript code, along with external stylesheets and scripts, directly into your Wor …
Is Easy Custom Code (LESS/CSS/JS) – Live Editing Safe to Use in 2026?
Generally Safe
Score 100/100Easy Custom Code (LESS/CSS/JS) – Live Editing has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'easy-custom-code' v1.1.2 plugin exhibits a generally positive security posture based on the static analysis, with no identified critical or high severity taint flows and a strong adherence to prepared statements for SQL queries. The high percentage of properly escaped output is also a good indicator of defensive coding practices. However, the complete absence of nonce checks and capability checks across all entry points, coupled with a recorded medium severity vulnerability in its history, presents notable concerns. The plugin's attack surface is currently minimal, which is beneficial, but the lack of fundamental security checks like nonces leaves it susceptible to potential attacks if new entry points are introduced or existing ones are exploited without proper authentication and authorization mechanisms in place. The historical vulnerability, categorized as Cross-site Scripting, and its recent occurrence highlight a recurring area that requires vigilant attention and robust preventative measures.
While the current static analysis shows a clean bill of health regarding specific code vulnerabilities, the lack of authentication and authorization checks on any potential entry points is a significant weakness. This means that any future addition of features, even seemingly innocuous ones, could inadvertently introduce severe security flaws. The plugin's history of a medium severity XSS vulnerability, even if patched, suggests that developers should maintain a heightened awareness of input sanitization and output escaping, particularly when dealing with user-supplied data. The plugin's strengths lie in its clean SQL handling and good output escaping, but these are overshadowed by the fundamental gaps in security controls.
Key Concerns
- No nonce checks present
- No capability checks present
- 1 medium severity vulnerability in history
- 10% of outputs not properly escaped
Easy Custom Code (LESS/CSS/JS) – Live Editing Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Easy Custom Code (LESS/CSS/JS) – Live editing <= 1.0.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
Easy Custom Code (LESS/CSS/JS) – Live Editing Release Timeline
Easy Custom Code (LESS/CSS/JS) – Live Editing Code Analysis
Output Escaping
Easy Custom Code (LESS/CSS/JS) – Live Editing Attack Surface
WordPress Hooks 19
Maintenance & Trust
Easy Custom Code (LESS/CSS/JS) – Live Editing Maintenance & Trust
Maintenance Signals
Community Trust
Easy Custom Code (LESS/CSS/JS) – Live Editing Alternatives
Live Custom CSS JS Code Editor
live-css-js-code-editor
Live Custom CSS JS Code Editor allows you to easily add custom CSS, JavaScript, Header, Footer Code to your site, straight from your WordPress Customi …
Tuxedo CSS Editor
tuxedo-css-editor
Realtime CSS editing in the customizer with Sass, Less and Autoprefixer support.
Asset CleanUp: Page Speed Booster
wp-asset-clean-up
Make your website load FASTER by stopping specific styles (.CSS) & scripts (.JS) from loading. It works best with a page caching plugin / service.
Simple CSS
simple-css
Add CSS to your website through an admin editor, the Customizer or a metabox for page/post specific CSS.
Scripts n Styles
scripts-n-styles
This plugin allows Admin users to individually add HTML, custom CSS, Classes and JavaScript directly to Post, Pages or any other custom post types.
Easy Custom Code (LESS/CSS/JS) – Live Editing Developer Profile
4 plugins · 30K total installs
How We Detect Easy Custom Code (LESS/CSS/JS) – Live Editing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-custom-code/admin/css/admin.min.css/wp-content/plugins/easy-custom-code/admin/js/admin.min.jseasy-custom-code/admin/css/admin.min.css?ver=easy-custom-code/admin/js/admin.min.js?ver=HTML / DOM Fingerprints
Easy Custom Code (LESS/CSS/JS) - Live editing for WordPress - v1.1.2 (free version) Author: Web357 Copyright © 2014-2025 Web357. All rights reserved. License: GNU/GPLv3, http://www.gnu.org/licenses/gpl-3.0.html +4 more