
Flat Preloader Security & Risk Analysis
wordpress.org/plugins/flat-preloaderFlat Preloader helps you create the loading page with many excited gif icons.
Is Flat Preloader Safe to Use in 2026?
Mostly Safe
Score 84/100Flat Preloader is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The 'flat-preloader' plugin v1.16.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are common areas for vulnerabilities. The presence of a nonce check and a focus on prepared statements are good security practices. However, concerns arise from the moderate rate of output escaping, with only 57% of outputs being properly sanitized. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially when considering the plugin's vulnerability history.
The vulnerability history of 'flat-preloader' shows a concerning pattern with two known medium-severity CVEs, both related to Cross-Site Scripting (Improper Neutralization of Input During Web Page Generation). While there are no currently unpatched vulnerabilities and the last known vulnerability was in 2021, the historical prevalence of XSS indicates a weakness in how user-supplied data is handled in the output phase. The lack of capability checks in the identified entry points (though zero in total) is also a minor concern, as it assumes that if any were introduced, they might not be adequately secured.
In conclusion, 'flat-preloader' v1.16.0 benefits from a minimal attack surface and strong practices in database interaction and external communication. However, the less than ideal output escaping and past XSS vulnerabilities present a notable risk. While no critical or high-severity issues were found in the static analysis, and there are no currently unpatched CVEs, the historical pattern warrants caution. Sites using this plugin should be vigilant about potential XSS vulnerabilities that may not have been caught in this specific analysis, and future updates should prioritize robust output escaping.
Key Concerns
- Moderate rate of unescaped output
- Past medium severity XSS vulnerabilities
Flat Preloader Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Flat Preloader < 1.5.5 - Stored Cross-Site Scripting
Flat Preloader <= 1.5.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Flat Preloader Code Analysis
Output Escaping
Data Flow Analysis
Flat Preloader Attack Surface
WordPress Hooks 5
Maintenance & Trust
Flat Preloader Maintenance & Trust
Maintenance Signals
Community Trust
Flat Preloader Alternatives
PageLoader Lite – Loading Screen
pageloader-lite
Add a simple to use, lightweight loading screen to your WordPress site. Great for branding!
Safelayout Cute Preloader – CSS3 WordPress Preloader
safelayout-cute-preloader
Easily add a pure CSS animated preloader to your WordPress website.
Preloader
the-preloader
The ultimate Preloader plugin for WordPress. Smart, flexible, and made for easy control. Add a preloader to your website easily in only 3 steps.
Icons Font Loader – Load Web Fonts and Icon Libraries
icons-font-loader
Load essential Flaticon webfonts into your WordPress site. Use icons anywhere on your site with simple integration, ensuring fast performance.
Web Icons
icon
Web Icons plugin gives you scalable vector icons that can instantly be customized. More than 2.5k icons available.
Flat Preloader Developer Profile
1 plugin · 3K total installs
How We Detect Flat Preloader
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flat-preloader/assets/css/flat-preloader.css/wp-content/plugins/flat-preloader/assets/css/flat-preloader-public.css/wp-content/plugins/flat-preloader/assets/js/flat-preloader.js/wp-content/plugins/flat-preloader/assets/img//wp-content/plugins/flat-preloader/assets/js/flat-preloader.jsflat-preloader/assets/css/flat-preloader.css?ver=flat-preloader/assets/css/flat-preloader-public.css?ver=flat-preloader/assets/js/flat-preloader.js?ver=HTML / DOM Fingerprints
flat-preloader-activeid="flat-preloader-overlay"flatPreloader