
EnvyPreloader – Website Preloader WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/envypreloaderEnvyPreloader is a WordPress plugin that helps you to create multiple preloader with different styles. There are lots of option for customize your plu …
Is EnvyPreloader – Website Preloader WordPress Plugin Safe to Use in 2026?
Generally Safe
Score 85/100EnvyPreloader – Website Preloader WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "envypreloader" v1.0.0 plugin exhibits a generally positive security posture, particularly concerning its handling of SQL queries and absence of recorded vulnerabilities. The plugin utilizes prepared statements for all its SQL queries, which is a strong indicator of preventing SQL injection attacks. Furthermore, the complete lack of any recorded CVEs, historical or current, suggests a well-maintained and secure codebase to date.
However, several areas raise concerns. The plugin's attack surface is entirely composed of shortcodes, totaling 20 entry points. While the static analysis reports zero unprotected entry points, the absence of nonce and capability checks on these shortcodes is a significant omission. This could leave the plugin vulnerable to CSRF attacks or unauthorized execution of shortcode functionalities if not properly secured at the application level or by the theme/other plugins. Additionally, the output escaping is only properly implemented in 59% of cases, which poses a moderate risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed to users.
In conclusion, while the plugin demonstrates strengths in its SQL handling and vulnerability history, the lack of robust security measures for its shortcode entry points and the subpar output escaping present tangible risks. Addressing these weaknesses is crucial for a more secure plugin.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Moderate output escaping (59% proper)
EnvyPreloader – Website Preloader WordPress Plugin Security Vulnerabilities
EnvyPreloader – Website Preloader WordPress Plugin Code Analysis
Output Escaping
EnvyPreloader – Website Preloader WordPress Plugin Attack Surface
Shortcodes 20
WordPress Hooks 27
Maintenance & Trust
EnvyPreloader – Website Preloader WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
EnvyPreloader – Website Preloader WordPress Plugin Alternatives
EnvyPopup – All-in-One Popup Management WordPress Plugin
envypopup
EnvyPopup is a WordPress popup plugin which allows you to create unlimited popup to notify your customers. This plugin has the options to add position …
Announceo – Scrolling Notification Bar
announceo-scrolling-notification-bar
Announceo – Scrolling Notification Bar lets you display important announcements, offers, or messages at the top of your website in a clean and distrac …
HashBar – Announcement, Notification Bar & Popup Campaign
hashbar-wp-notification-bar
Create Announcement Bars, Notification Bars & Popup Campaigns with countdown timers, A/B testing, smart targeting & analytics.
Announcement & Notification Banner – Bulletin
bulletin-announcements
Publish a slick announcement banner notice across your website or Woocommerce shop. Extend with icons, countdowns, placement rules and more!
Popups for WooCommerce: Add to Cart, Checkout & More
popup-notices-for-woocommerce
Make your WooCommerce Notices (sucess, info, and error) more visible to your customers by turning them into popups
EnvyPreloader – Website Preloader WordPress Plugin Developer Profile
7 plugins · 60 total installs
How We Detect EnvyPreloader – Website Preloader WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/envy-preloader/admin/css/envy-preloader-admin.css/wp-content/plugins/envy-preloader/public/css/envy-preloader-public.css/wp-content/plugins/envy-preloader/public/js/envy-preloader-public.js/wp-content/plugins/envy-preloader/public/js/envy-preloader-public.jsenvy-preloader/admin/css/envy-preloader-admin.css?ver=envy-preloader/public/css/envy-preloader-public.css?ver=envy-preloader/public/js/envy-preloader-public.js?ver=HTML / DOM Fingerprints
envy-preloader-wrapper