Enqueue Me Security & Risk Analysis

wordpress.org/plugins/enqueue-me

Easily enqueue your favourite javascript and CSS libraries from an open-source package library. Designed specifically for WordPress theme developers.

10 active installs v0.5 PHP + WP 3.1+ Updated Unknown
enqueuelibrarypackagescriptstyle
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Enqueue Me Safe to Use in 2026?

Generally Safe

Score 100/100

Enqueue Me has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "enqueue-me" plugin v0.5 presents a significant security risk due to its unprotected AJAX handlers. All five identified AJAX entry points lack authentication checks, meaning any unauthenticated user could potentially trigger these actions. While the plugin demonstrates good practices by not using dangerous functions and employing prepared statements for SQL, the complete absence of capability checks and nonce verification on these critical entry points leaves it highly vulnerable to unauthorized execution of plugin functionalities. The absence of any recorded vulnerabilities in its history is positive, but it does not mitigate the severe risks identified in the static analysis. The plugin's security posture is concerning primarily because the identified attack surface is completely exposed.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX handlers
  • Missing capability checks on AJAX handlers
  • Taint analysis shows unsanitized paths
  • Output escaping is not fully proper
Vulnerabilities
None known

Enqueue Me Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Enqueue Me Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
35 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

59% escaped59 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
enq_me_update_sync_id_ajax (inc\admin.php:410)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Enqueue Me Attack Surface

Entry Points5
Unprotected5

AJAX Handlers 5

authwp_ajax_enq_me_update_timestampinc\admin.php:422
authwp_ajax_enq_me_update_enqueue_listinc\admin.php:442
authwp_ajax_enq_me_save_licence_detailsinc\admin.php:465
authwp_ajax_enq_me_get_optionsinc\import-export.php:69
authwp_ajax_enq_me_set_optionsinc\import-export.php:105
WordPress Hooks 10
actionplugins_loadedenqueue-me.php:32
actionadmin_menuenqueue-me.php:47
actionadmin_initinc\admin.php:54
actionwp_enqueue_scriptsinc\core.php:58
actionenq_me_in_wrapinc\fav-lists.php:34
actionadmin_enqueue_scriptsinc\fav-lists.php:72
actionenq_me_after_core_settingsinc\import-export.php:27
actionenq_me_before_core_settingsinc\import-export.php:36
actionadmin_enqueue_scriptsinc\import-export.php:47
actionadmin_enqueue_scriptsinc\load-scripts.php:86
Maintenance & Trust

Enqueue Me Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Enqueue Me Developer Profile

MagicStick

2 plugins · 410 total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Enqueue Me

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/enqueue-me/inc/core.php/wp-content/plugins/enqueue-me/inc/admin.php/wp-content/plugins/enqueue-me/inc/load-scripts.php/wp-content/plugins/enqueue-me/inc/import-export.php/wp-content/plugins/enqueue-me/inc/fav-lists.php

HTML / DOM Fingerprints

CSS Classes
forbidden-fruitenqueueme-settingsem-packages-selectmy-enqueue-wrapmy-enqueue-head
Data Attributes
id="root-dep-box"id="licenece-box"id="licenece-email-box"id="update-licence"
JS Globals
plugins_url
FAQ

Frequently Asked Questions about Enqueue Me