
jcwp capslock detection Security & Risk Analysis
wordpress.org/plugins/jcwp-capslock-detectionThis plugin shows a tooltip when user's have their CAPS lock on while typing their password to login.
Is jcwp capslock detection Safe to Use in 2026?
Generally Safe
Score 85/100jcwp capslock detection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The jcwp-capslock-detection plugin v1.09 exhibits a seemingly strong security posture from static analysis and vulnerability history. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-sized attack surface. The code also shows no signs of dangerous functions, file operations, external HTTP requests, or bundled libraries. SQL queries are exclusively prepared, and there are no recorded vulnerabilities in its history. This suggests the plugin is lightweight and focused, with no obvious direct entry points for malicious activity or known past security flaws.
However, the static analysis reveals significant concerns regarding output escaping. With 100% of its outputs not properly escaped, any data processed and displayed by the plugin is vulnerable to cross-site scripting (XSS) attacks. This is a critical oversight, as unescaped output allows attackers to inject malicious scripts into web pages, potentially stealing user data or hijacking sessions. While the absence of other vulnerability types is positive, the lack of output escaping creates a substantial risk that could be exploited even with a minimal attack surface.
In conclusion, while the plugin benefits from a small attack surface and a clean vulnerability history, the complete lack of output escaping is a major weakness. This flaw presents a clear and present danger of XSS vulnerabilities. Users of this plugin should be aware that while direct code injection or SQL injection might be unlikely due to the plugin's structure and coding practices, the risk of XSS is very high. Further investigation into the actual output mechanisms of the plugin would be prudent.
Key Concerns
- 0% of output properly escaped
jcwp capslock detection Security Vulnerabilities
jcwp capslock detection Release Timeline
jcwp capslock detection Code Analysis
Output Escaping
jcwp capslock detection Attack Surface
WordPress Hooks 4
Maintenance & Trust
jcwp capslock detection Maintenance & Trust
Maintenance Signals
Community Trust
jcwp capslock detection Alternatives
ToolTips For Contact Form 7
tool-tips-for-contact-form-7
Contact Form 7 Tooltips is Extremely easy Configurable. Each Form Has Own Configuration. So, Each Contact Form 7 Tooltips Can be set Uniquely.
PicTips
pictips
PicTips provides a shortcode for images to be used as ToolTips. Like ToolTips but with pictures.
jcwp capslock detection Developer Profile
9 plugins · 590 total installs
How We Detect jcwp capslock detection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jcwp-capslock-detection/jccapslock.js/wp-content/plugins/jcwp-capslock-detection/jccapslock.cssjccapslock.jsjcorgcld_scriptjcorgcld_stylesHTML / DOM Fingerprints
jcorgbsuccessjcorgberrorjcorgb-errors-titlejcorgb-errorsjcorgcld_activejcorgcld_fallbackjcorgcld_positionjcorgcld_fadejcorgcld_htmljcorgcld_offset+2 moreCapsLockAlert<a style="font-size:0em !important;color:transparent !important" href="http://jaspreetchahal.org">Scroll to top is powered by http://jaspreetchahal.org</a>