
Enable Latex Security & Risk Analysis
wordpress.org/plugins/enable-latexInsert LaTeX formulas in your posts.
Is Enable Latex Safe to Use in 2026?
Use With Caution
Score 63/100Enable Latex has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'enable-latex' plugin exhibits a concerning security posture, largely due to a significant number of unprotected AJAX handlers and widespread issues with output escaping. The static analysis reveals 8 AJAX handlers, all lacking authentication checks, which represent a substantial attack surface. Furthermore, only a meager 4% of output operations are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities being present throughout the plugin's functionality. The presence of the `unserialize` function, without clear sanitization context provided in the data, is another red flag that could lead to remote code execution if improperly handled serialized data is processed.
Taint analysis showed no critical or high severity flows, which is a positive sign. However, the vulnerability history, including a known medium-severity CVE that remains unpatched, suggests a pattern of past security weaknesses and a potential lack of proactive security maintenance. The plugin's history of Cross-Site Request Forgery (CSRF) vulnerabilities, coupled with the numerous unprotected AJAX endpoints, further amplifies this concern. While the plugin has some strengths, such as a moderate SQL query preparedness and no bundled libraries, the overwhelming number of unprotected entry points and poor output escaping practices create a high-risk environment.
Key Concerns
- Unprotected AJAX handlers
- Low output escaping coverage
- Unpatched medium CVE
- No nonce checks
- Dangerous function unserialize
- Low capability check coverage
Enable Latex Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Enable Latex <= 1.2.16 - Cross-Site Request Forgery
Enable Latex Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Enable Latex Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 26
Maintenance & Trust
Enable Latex Maintenance & Trust
Maintenance Signals
Community Trust
Enable Latex Alternatives
Insert math
insert-math
Fast and handy insert any math formulas in your posts.
MathJax-LaTeX
mathjax-latex
This plugin enables MathJax (http://www.mathjax.org) functionality for WordPress (http://www.wordpress.org).
WP QuickLaTeX
wp-quicklatex
Advanced LaTeX plugin. Native LaTeX syntax. Allows custom preamble, TikZ and other packages. Zoom-independent visual quality (SVG).
Simple Mathjax
simple-mathjax
Yet another plugin to add MathJax support to your wordpress blog. Just wrap your equations inside $ signs and MathJax will render them visually.
KaTeX
katex
Use the fastest math typesetting library on your website.
Enable Latex Developer Profile
14 plugins · 31K total installs
How We Detect Enable Latex
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/enable-latex/assets/css/main.css/wp-content/plugins/enable-latex/assets/js/scripts.js/wp-content/plugins/enable-latex/assets/css/tooltip.css/wp-content/plugins/enable-latex/assets/js/tooltip.js/wp-content/plugins/enable-latex/assets/js/mathjax.js/wp-content/plugins/enable-latex/assets/js/scripts.js/wp-content/plugins/enable-latex/assets/js/tooltip.js/wp-content/plugins/enable-latex/assets/js/mathjax.jsenable-latex/assets/css/main.css?ver=enable-latex/assets/js/scripts.js?ver=enable-latex/assets/css/tooltip.css?ver=enable-latex/assets/js/tooltip.js?ver=enable-latex/assets/js/mathjax.js?ver=HTML / DOM Fingerprints
latex_objectlatex_img_objectlatex_img_text<!-- latex --><!-- end latex -->data-latex-codedata-latex-typeEnableLatex/wp-json/enable-latex/v1/settings[latex][/latex]