Insert Code Lite Security & Risk Analysis

wordpress.org/plugins/insert-code-lite

Insert Code Lite lets you add scripts, styles, and other custom code to your website.

80 active installs v0.1.4 PHP + WP 3.9.2+ Updated Dec 4, 2018
admincounterjavascripttrackingtracking-code
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Insert Code Lite Safe to Use in 2026?

Generally Safe

Score 85/100

Insert Code Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The Insert-Code-Lite plugin v0.1.4 exhibits a strong security posture based on the provided static analysis. The plugin reports zero entry points into its code that are unprotected, which is a significant positive indicator. Furthermore, the code signals show no dangerous functions, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, all of which are excellent security practices. The presence of capability checks and the lack of bundled libraries also contribute to its robust security. The vulnerability history is also clear, with no known CVEs, indicating a history of stable and secure development.

While the static analysis is overwhelmingly positive, a minor area for attention is the output escaping. With 7 total outputs and 29% not properly escaped (approximately 2 outputs), there is a small potential for cross-site scripting (XSS) vulnerabilities if user-supplied data were to influence these unescaped outputs. However, given the absence of any identified taint flows or specific vulnerability types in its history, this risk appears to be minimal in practice. Overall, the plugin demonstrates a commendable commitment to security, with the only slight concern being the incomplete output escaping.

Key Concerns

  • Output escaping incomplete (approx. 29%)
Vulnerabilities
None known

Insert Code Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Insert Code Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped7 total outputs
Attack Surface

Insert Code Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedincludes\class-insert-code-lite.php:132
actionadmin_menuincludes\class-insert-code-lite.php:143
actionadmin_initincludes\class-insert-code-lite.php:144
actionwp_headincludes\class-insert-code-lite.php:155
actionwp_footerincludes\class-insert-code-lite.php:156
Maintenance & Trust

Insert Code Lite Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 4, 2018
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs80
Developer Profile

Insert Code Lite Developer Profile

Dmitry Mayorov

2 plugins · 680 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Insert Code Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/insert-code-lite/public/css/insert-code-lite-public.css
Script Paths
/wp-content/plugins/insert-code-lite/public/js/insert-code-lite-public.js
Version Parameters
insert-code-lite/public/css/insert-code-lite-public.css?ver=insert-code-lite/public/js/insert-code-lite-public.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Insert Code Lite