Init FX Engine – Interactive, Event-Driven, Lightweight Security & Risk Analysis

wordpress.org/plugins/init-fx-engine

Bring your WordPress site to life with interactive visual effects triggered by keywords, comments, and special occasions.

90 active installs v1.6.1 PHP 7.4+ WP 5.5+ Updated Dec 25, 2025
animationcommentconfettieffectinteraction
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Init FX Engine – Interactive, Event-Driven, Lightweight Safe to Use in 2026?

Generally Safe

Score 100/100

Init FX Engine – Interactive, Event-Driven, Lightweight has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The init-fx-engine plugin version 1.6.1 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The code demonstrates strong adherence to security best practices, with 100% of SQL queries using prepared statements and 99% of output being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a robust defense against common attack vectors. Furthermore, the plugin has no recorded vulnerabilities or CVEs, indicating a history of secure development and maintenance.

However, there are a few areas that, while not currently presenting immediate critical risks according to the analysis, warrant attention. The presence of four shortcodes, while not explicitly noted as unprotected, represents potential entry points that could become problematic if future updates introduce vulnerabilities or if they interact with other plugins in unexpected ways. The lack of nonce checks across all entry points is a notable weakness, as nonces are a fundamental defense mechanism against Cross-Site Request Forgery (CSRF) attacks. While there are no current indications of taint flow issues, the absence of taint analysis results means this aspect hasn't been fully scrutinized, and a deeper dive might reveal subtle vulnerabilities.

In conclusion, init-fx-engine v1.6.1 is a well-developed plugin with a strong security foundation. Its clean code, secure SQL practices, and lack of vulnerability history are commendable. The primary areas for improvement lie in implementing nonce checks for all entry points and ensuring a thorough review of shortcode functionalities. The limited scope of the static analysis, particularly regarding taint flows, suggests that continued vigilance and potentially deeper security audits in the future would be beneficial to maintain its excellent security record.

Key Concerns

  • No nonce checks on entry points
Vulnerabilities
None known

Init FX Engine – Interactive, Event-Driven, Lightweight Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Init FX Engine – Interactive, Event-Driven, Lightweight Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
67 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped68 total outputs
Attack Surface

Init FX Engine – Interactive, Event-Driven, Lightweight Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[initfxen-fx] includes\shortcodes.php:33
[init-fx] includes\shortcodes.php:34
[initfxen-fx-ambient] includes\shortcodes.php:134
[init-fx-ambient] includes\shortcodes.php:135
WordPress Hooks 9
actionadmin_menuincludes\settings-page.php:5
actionadmin_enqueue_scriptsincludes\settings-page.php:16
actionadmin_initincludes\settings-page.php:46
actionwp_enqueue_scriptsinit-fx-engine.php:38
actionwp_headinit-fx-engine.php:106
actionwp_enqueue_scriptsinit-fx-engine.php:274
actionwp_footerinit-fx-engine.php:304
actionwp_enqueue_scriptsinit-fx-engine.php:330
actionwp_enqueue_scriptsinit-fx-engine.php:441
Maintenance & Trust

Init FX Engine – Interactive, Event-Driven, Lightweight Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 25, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

Init FX Engine – Interactive, Event-Driven, Lightweight Developer Profile

Init HTML

12 plugins · 710 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Init FX Engine – Interactive, Event-Driven, Lightweight

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/init-fx-engine/assets/js/canvas-confetti.min.js/wp-content/plugins/init-fx-engine/assets/js/fx-engine.js
Script Paths
/wp-content/plugins/init-fx-engine/assets/js/canvas-confetti.min.js/wp-content/plugins/init-fx-engine/assets/js/fx-engine.js
Version Parameters
init-fx-engine/assets/js/canvas-confetti.min.js?ver=init-fx-engine/assets/js/fx-engine.js?ver=

HTML / DOM Fingerprints

CSS Classes
init-fx-preloadingfx-animate-out
HTML Comments
PRELOADER - Anti-flash solution (FIXED VERSION) - Che content ngay từ đầu bằng CSS critical - Preloader show immediately, content hidden cho đến khi ready - Fixed z-index và visibility issues
Data Attributes
id="init-fx-critical-preloader"id="init-fx-preloader"
JS Globals
window.INIT_FX.inlinefmtwindow.INIT_FX.i18nwindow.INIT_FX.preloaderFX_KEYWORDS
FAQ

Frequently Asked Questions about Init FX Engine – Interactive, Event-Driven, Lightweight