
Enable CORS Security & Risk Analysis
wordpress.org/plugins/enable-corsPlease read the plugin description before installing to ensure compatibility and avoid potential issues. This plugin will be free forever.
Is Enable CORS Safe to Use in 2026?
Generally Safe
Score 100/100Enable CORS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'enable-cors' plugin v2.0.2 exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events indicates a minimal attack surface. Crucially, all observed code signals are positive: no dangerous functions are used, SQL queries are 100% prepared, and all output is properly escaped. The presence of one capability check further suggests an attempt at securing functionalities, even if the attack surface is currently zero.
The taint analysis reveals no identified flows with unsanitized paths, and the vulnerability history is clean with zero known CVEs. This lack of historical issues and the current static analysis findings paint a picture of a well-developed and secure plugin. The primary strength lies in its simplicity and adherence to secure coding practices, with no apparent vulnerabilities or potential exploit vectors identified in this version.
However, the analysis does highlight a few areas for potential improvement, albeit minor given the current state. The lack of nonce checks on the zero AJAX handlers is technically a missed opportunity for security, even if it poses no immediate risk due to the absence of those handlers. Similarly, the capability check, while present, might be more of a placeholder if there are no actual user-facing features to protect. Overall, the plugin is highly secure for its current version, with its simplicity being its greatest asset.
Key Concerns
- Missing nonce checks on AJAX handlers
Enable CORS Security Vulnerabilities
Enable CORS Code Analysis
Output Escaping
Enable CORS Attack Surface
WordPress Hooks 9
Maintenance & Trust
Enable CORS Maintenance & Trust
Maintenance Signals
Community Trust
Enable CORS Alternatives
Ajaxify Comments – Ajax and Lazy Loading Comments
wp-ajaxify-comments
Ajaxify Comments hooks into native WordPress comments and allows comment posting without reloading the page.
Hatom/hentry remover (Fixes errors in Google Webmaster Tools)
no-hentry
This plugin removes the ".hentry" class with a post_class-filter and supports all themes (even the Twenty T*-family) by simply adding the ta …
WP-CORS
wp-cors
Allows AJAX requests from other sites to integrate content from your site using the CORS standard.
LH Multisite CORS
lh-multisite-cors
Allows AJAX requests from other sites in your multisite network even if they are on another domain or subdomain
Simple Database Repair
simple-database-repair
Repair table fixes any corrupted table .
Enable CORS Developer Profile
1 plugin · 6K total installs
How We Detect Enable CORS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/enable-cors/assets/dist/main.css/wp-content/plugins/enable-cors/assets/dist/main.jsenable-cors/assets/dist/main.css?ver=enable-cors/assets/dist/main.js?ver=HTML / DOM Fingerprints
enable-corsenableCors/wp-json/enable-cors/v2.0.2/settings