Iris Color Picker Enhancer Security & Risk Analysis

wordpress.org/plugins/iris-color-picker-enhancer

Customise the default color palette used by Iris Color Picker

20 active installs v1.1 PHP + WP 2.7+ Updated Sep 8, 2017
alphacolor-swatchesirisiris-coloriris-color-picker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Iris Color Picker Enhancer Safe to Use in 2026?

Generally Safe

Score 85/100

Iris Color Picker Enhancer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of the 'iris-color-picker-enhancer' v1.1 plugin reveals a generally good security posture in terms of attack surface and potential for direct code execution. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct entry points for attackers to exploit. Furthermore, the plugin avoids dangerous functions and does not perform file operations or external HTTP requests, which are common vectors for vulnerabilities. The use of prepared statements for SQL queries is also a strong positive indicator of secure database interaction.

However, a significant concern arises from the output escaping analysis. With 22 outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the frontend or within the WordPress admin area without proper sanitization or escaping can be manipulated by attackers to inject malicious scripts. The absence of nonce and capability checks across all identified entry points (though there are none) is noted, but the critical lack of output escaping is the most prominent vulnerability risk.

The vulnerability history being entirely clear with no recorded CVEs is a positive sign, suggesting the developers may be security-conscious or that the plugin has not yet been targeted or thoroughly audited for public vulnerabilities. This history, combined with the lack of exploitable entry points, suggests a plugin that, on the surface, appears robust. However, the severe lack of output escaping overshadows these positives, creating a significant XSS risk that requires immediate attention.

Key Concerns

  • Outputs not properly escaped
Vulnerabilities
None known

Iris Color Picker Enhancer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Iris Color Picker Enhancer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped22 total outputs
Attack Surface

Iris Color Picker Enhancer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuiris-color-picker-enhancer.php:26
actionadmin_initiris-color-picker-enhancer.php:41
actionadmin_enqueue_scriptsiris-color-picker-enhancer.php:63
actionadmin_footeriris-color-picker-enhancer.php:76
actioncustomize_controls_print_footer_scriptsiris-color-picker-enhancer.php:77
actionadmin_noticesiris-color-picker-enhancer.php:119
actionadmin_headiris-color-picker-enhancer.php:149
actionadmin_headiris-color-picker-enhancer.php:150
Maintenance & Trust

Iris Color Picker Enhancer Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 8, 2017
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs20
Developer Profile

Iris Color Picker Enhancer Developer Profile

Maeve Lander

6 plugins · 11K total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
29 days
View full developer profile
Detection Fingerprints

How We Detect Iris Color Picker Enhancer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/iris-color-picker-enhancer/assets/js/wp-color-picker-alpha.min.js/wp-content/plugins/iris-color-picker-enhancer/assets/css/alpha-color-picker.css
Script Paths
/wp-content/plugins/iris-color-picker-enhancer/assets/js/wp-color-picker-alpha.min.js

HTML / DOM Fingerprints

CSS Classes
icpe-fieldicpe-left-contenticpe-settings-body
JS Globals
ICPE_PLUGIN_URIicpe_color_palettes1icpe_color_palettes2icpe_color_palettes3icpe_color_palettes4icpe_color_palettes5+2 more
FAQ

Frequently Asked Questions about Iris Color Picker Enhancer