JetStyleManager for Gutenberg Security & Risk Analysis

wordpress.org/plugins/jet-style-manager

A plugin that extends Gutenberg functionality. Integrated to a Gutenberg plugin, JetStyleManager allows adding styles to it.

20K active installs v1.3.8 PHP 7.2+ WP 5.6+ Updated Aug 20, 2024
blocksgutenbergstylestyles-manager
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JetStyleManager for Gutenberg Safe to Use in 2026?

Generally Safe

Score 92/100

JetStyleManager for Gutenberg has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "jet-style-manager" plugin v1.3.8 exhibits a generally good security posture in several key areas. All identified AJAX entry points include capability checks, and there are no unescaped outputs, dangerous functions, or file operations, which are positive indicators. The plugin also demonstrates good practice with SQL queries, as 67% utilize prepared statements. However, the static analysis reveals potential concerns regarding unsanitized paths identified in two taint flows, both flagged as high severity. While the plugin has no recorded vulnerability history, these taint flows represent an immediate risk that needs attention. The absence of nonce checks on AJAX handlers, combined with the presence of high-severity unsanitized path flows, suggests a potential for attackers to exploit these weaknesses if they can trigger the affected code paths. Therefore, while the plugin has strengths in output escaping and capability checks, the identified taint issues and lack of nonce protection warrant careful consideration.

Key Concerns

  • High severity taint flow with unsanitized path
  • High severity taint flow with unsanitized path
  • No nonce checks on AJAX handlers
Vulnerabilities
None known

JetStyleManager for Gutenberg Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

JetStyleManager for Gutenberg Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
4 prepared
Unescaped Output
0
17 escaped
Nonce Checks
0
Capability Checks
6
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

67% prepared6 total queries

Output Escaping

100% escaped17 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
load_preview_skin_css (includes\elementor\skins.php:146)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

JetStyleManager for Gutenberg Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_jet_sm_save_skinincludes\elementor\skins.php:135
authwp_ajax_jet_sm_delete_skinincludes\elementor\skins.php:136
authwp_ajax_jet_sm_get_skins_for_widgetincludes\elementor\skins.php:137
authwp_ajax_jet_sm_apply_skinincludes\elementor\skins.php:138
authwp_ajax_jet_sm_load_skins_cssincludes\elementor\skins.php:139
WordPress Hooks 25
actionelementor/css-file/post/enqueueincludes\elementor\css-render.php:30
actionelementor/preview/enqueue_stylesincludes\elementor\css-render.php:31
actionjet-styles-manager/css-stack/resetincludes\elementor\css-render.php:33
actionelementor/element/before_parse_cssincludes\elementor\css-stack.php:34
actionelementor/document/after_saveincludes\elementor\css-stack.php:35
actionelementor/element/parse_cssincludes\elementor\css-stack.php:82
actionelementor/css-file/post/parseincludes\elementor\css-stack.php:83
actionelementor/element/common/_section_attributes/before_section_endincludes\elementor\skins.php:29
actionelementor/widget/before_render_contentincludes\elementor\skins.php:34
actionelementor/editor/after_enqueue_scriptsincludes\elementor\skins.php:39
actionelementor/editor/before_enqueue_scriptsincludes\elementor\skins.php:134
actionenqueue_block_assetsincludes\gutenberg\block-manager.php:45
actionenqueue_block_editor_assetsincludes\gutenberg\block-manager.php:46
actionenqueue_block_editor_assetsincludes\gutenberg\block-manager.php:47
filteradmin_body_classincludes\gutenberg\block-manager.php:48
actionwp_enqueue_scriptsincludes\gutenberg\controls-stack.php:22
actionadmin_enqueue_scriptsincludes\gutenberg\controls-stack.php:23
filterregister_block_type_argsincludes\gutenberg\controls-stack.php:24
actioninitincludes\gutenberg\style-manager.php:22
actionwp_print_footer_scriptsincludes\gutenberg\style-manager.php:23
actionwp_print_footer_scriptsincludes\gutenberg\style-manager.php:24
actionadmin_print_footer_scriptsincludes\gutenberg\style-manager.php:25
filterrender_blockincludes\gutenberg\style-manager.php:27
actioninitincludes\plugin.php:41
actionplugins_loadedjet-style-manager.php:26
Maintenance & Trust

JetStyleManager for Gutenberg Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 20, 2024
PHP min version7.2
Downloads209K

Community Trust

Rating52/100
Number of ratings9
Active installs20K
Developer Profile

JetStyleManager for Gutenberg Developer Profile

jetmonsters

33 plugins · 326K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
193 days
View full developer profile
Detection Fingerprints

How We Detect JetStyleManager for Gutenberg

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jet-style-manager/assets/css/jet-style-manager-frontend.css/wp-content/plugins/jet-style-manager/assets/js/jet-style-manager-frontend.js/wp-content/plugins/jet-style-manager/assets/css/jet-style-manager-editor.css/wp-content/plugins/jet-style-manager/assets/js/jet-style-manager-editor.js
Script Paths
/wp-content/plugins/jet-style-manager/assets/js/jet-style-manager-frontend.js/wp-content/plugins/jet-style-manager/assets/js/jet-style-manager-editor.js
Version Parameters
jet-style-manager/assets/css/jet-style-manager-frontend.css?ver=jet-style-manager/assets/js/jet-style-manager-frontend.js?ver=jet-style-manager/assets/css/jet-style-manager-editor.css?ver=jet-style-manager/assets/js/jet-style-manager-editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
jet-sm-advanced-html
Data Attributes
jet_sm_skin
JS Globals
JetSMRenderedSkinsJetSM_Settings
REST Endpoints
/wp-json/jet-style-manager/v1/settings/wp-json/jet-style-manager/v1/save-settings
Shortcode Output
[jet-sm-advanced-html]
FAQ

Frequently Asked Questions about JetStyleManager for Gutenberg