
GitHub Code Viewer Security & Risk Analysis
wordpress.org/plugins/githubGitHub Code Viewer automatically pulls a file from and displays it in a blog post.
Is GitHub Code Viewer Safe to Use in 2026?
Generally Safe
Score 85/100GitHub Code Viewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "github" v1.0 plugin exhibits a generally strong security posture based on the static analysis provided. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output appears to be properly escaped. The plugin also avoids file operations and external HTTP requests, further reducing potential attack vectors. The absence of any recorded vulnerabilities in its history is a positive indicator of past development practices.
However, the analysis also highlights significant areas of concern. The plugin has zero capability checks and zero nonce checks across its entry points. While the attack surface is currently small (0 entry points), this lack of fundamental security checks means that if any new entry points were introduced, they would be immediately unprotected. This is a critical oversight that could lead to severe vulnerabilities if the plugin evolves or if unexpected entry points are discovered.
In conclusion, while the current code for "github" v1.0 demonstrates good technical practices in areas like SQL and output handling, the complete absence of capability and nonce checks is a major weakness. The plugin's vulnerability history is clean, but this is likely due to its limited functionality and attack surface. The lack of built-in security checks presents a substantial risk for future development or exposure to unintended access.
Key Concerns
- No capability checks
- No nonce checks
GitHub Code Viewer Security Vulnerabilities
GitHub Code Viewer Release Timeline
GitHub Code Viewer Code Analysis
SQL Query Safety
GitHub Code Viewer Attack Surface
WordPress Hooks 1
Maintenance & Trust
GitHub Code Viewer Maintenance & Trust
Maintenance Signals
Community Trust
GitHub Code Viewer Alternatives
GetGit
getgit
Embeds syntax-highlighted GitHub repo content into your blog posts.
WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager
insert-headers-and-footers
Easily add code snippets in WordPress. Insert header & footer scripts, add PHP code snippets with conditional logic, insert ads pixel code, and more.
Code Snippets
code-snippets
An easy, clean and simple way to enhance your site with code snippets.
Header Footer Code Manager
header-footer-code-manager
Easily add tracking code snippets, conversion pixels, or other scripts required by third party services for analytics, marketing, or chat features.
Insert PHP Code Snippet
insert-php-code-snippet
Add PHP code to your pages and posts easily using shortcodes.
GitHub Code Viewer Developer Profile
2 plugins · 20 total installs
How We Detect GitHub Code Viewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
httpc://