JavaScript Framebreaker Security & Risk Analysis

wordpress.org/plugins/javascript-framebreaker

Adds a framebreaker JavaScript function to the header for breaking out of the former Google Image Search and other framesets.

10 active installs v1.1 PHP + WP 3.3.1+ Updated Jun 18, 2019
breakframeframesjavascriptjs
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JavaScript Framebreaker Safe to Use in 2026?

Generally Safe

Score 85/100

JavaScript Framebreaker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'javascript-framebreaker' plugin version 1.1 exhibits an excellent security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or taint flows with unsanitized paths is a strong indicator of well-written and secure code. Furthermore, the complete lack of any recorded vulnerabilities in its history, including CVEs, suggests a history of diligent security practices by the developers.

The most notable aspect of this analysis is the extremely small attack surface. With zero AJAX handlers, REST API routes, shortcodes, or cron events, the plugin has no direct entry points that could be exploited by external input. The fact that all (zero) of these potential entry points are also noted as unprotected (zero) reinforces this. However, the complete absence of nonce and capability checks is a potential area of concern, though it is mitigated by the lack of any exploitable entry points. If future versions introduce any such points, these checks would become critical.

In conclusion, 'javascript-framebreaker' v1.1 appears to be a highly secure plugin due to its minimal attack surface and absence of identified vulnerabilities. The code analysis further supports this with strong adherence to secure coding practices. The only minor point of note is the lack of explicit security checks on potential entry points, but this is rendered moot by the current lack of such entry points. This plugin demonstrates a strong commitment to security.

Key Concerns

  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

JavaScript Framebreaker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

JavaScript Framebreaker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

JavaScript Framebreaker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwp_headwp_framebreaker.php:35
Maintenance & Trust

JavaScript Framebreaker Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 18, 2019
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

JavaScript Framebreaker Developer Profile

Kai Spriestersbach

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect JavaScript Framebreaker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/javascript-framebreaker/wp_framebreaker.php

HTML / DOM Fingerprints

JS Globals
window.onload
FAQ

Frequently Asked Questions about JavaScript Framebreaker