
JavaScript Framebreaker Security & Risk Analysis
wordpress.org/plugins/javascript-framebreakerAdds a framebreaker JavaScript function to the header for breaking out of the former Google Image Search and other framesets.
Is JavaScript Framebreaker Safe to Use in 2026?
Generally Safe
Score 85/100JavaScript Framebreaker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'javascript-framebreaker' plugin version 1.1 exhibits an excellent security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or taint flows with unsanitized paths is a strong indicator of well-written and secure code. Furthermore, the complete lack of any recorded vulnerabilities in its history, including CVEs, suggests a history of diligent security practices by the developers.
The most notable aspect of this analysis is the extremely small attack surface. With zero AJAX handlers, REST API routes, shortcodes, or cron events, the plugin has no direct entry points that could be exploited by external input. The fact that all (zero) of these potential entry points are also noted as unprotected (zero) reinforces this. However, the complete absence of nonce and capability checks is a potential area of concern, though it is mitigated by the lack of any exploitable entry points. If future versions introduce any such points, these checks would become critical.
In conclusion, 'javascript-framebreaker' v1.1 appears to be a highly secure plugin due to its minimal attack surface and absence of identified vulnerabilities. The code analysis further supports this with strong adherence to secure coding practices. The only minor point of note is the lack of explicit security checks on potential entry points, but this is rendered moot by the current lack of such entry points. This plugin demonstrates a strong commitment to security.
Key Concerns
- Lack of nonce checks
- Lack of capability checks
JavaScript Framebreaker Security Vulnerabilities
JavaScript Framebreaker Code Analysis
JavaScript Framebreaker Attack Surface
WordPress Hooks 1
Maintenance & Trust
JavaScript Framebreaker Maintenance & Trust
Maintenance Signals
Community Trust
JavaScript Framebreaker Alternatives
BJ Lazy Load
bj-lazy-load
Lazy loading for images and iframes makes your site load faster and saves bandwidth. Uses no external JS libraries and degrades gracefully for non-js …
Break Out of Frames
break-out-of-frames
This Framebreaker will Avoid your blog being framed by some other web site and good for wallpaper blog to increase traffic.
WP Frame Breaker
wp-frame-breaker
Adds a short javascript to your blog header to break out of any containing frames
Frame Breaker
frame-breaker-removes-digg-bar-owly-bar-facebook-bar-etc
You want people to visit your website rather than be stuck in a frame or iframe, you need this plugin.
Qi Blocks
qi-blocks
Qi Blocks is the largest collection of Gutenberg blocks developed by Qode Interactive.
JavaScript Framebreaker Developer Profile
1 plugin · 10 total installs
How We Detect JavaScript Framebreaker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/javascript-framebreaker/wp_framebreaker.phpHTML / DOM Fingerprints
window.onload