Js Css Include Manager Security & Risk Analysis

wordpress.org/plugins/js-css-include-manager

This plug-in is a will clean the file management. You can only manage the screen. You can also only site the screen.

30 active installs v1.4.4 PHP + WP 3.8+ Updated Sep 24, 2015
cssincludejavascriptjsmanage
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Js Css Include Manager Safe to Use in 2026?

Generally Safe

Score 85/100

Js Css Include Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "js-css-include-manager" plugin v1.4.4 demonstrates a generally strong security posture with several good practices in place. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the plugin exclusively uses prepared statements for SQL queries, mitigating the risk of SQL injection vulnerabilities. The presence of nonce and capability checks, along with the limited number of file operations and external HTTP requests, are also positive security indicators.

However, a significant concern arises from the output escaping. With only 25% of the 91 output instances properly escaped, there is a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. This means that data displayed to users might not be sufficiently sanitized, allowing attackers to inject malicious scripts. The single unsanitized path flow identified in the taint analysis, though not classified as critical or high severity, further reinforces the potential for path traversal or similar vulnerabilities if not addressed. The plugin's clean vulnerability history is a strength, suggesting a history of stable development, but it does not negate the risks identified in the current code analysis.

In conclusion, while the plugin's minimal attack surface and secure SQL handling are commendable, the prevalent lack of proper output escaping and the identified unsanitized path flow present tangible security risks. Addressing the output escaping and the unsanitized path is crucial to improving its overall security. The plugin's clean history is a positive sign, but the current analysis reveals areas that require immediate attention to ensure user data and site integrity.

Key Concerns

  • Poor output escaping (25% properly escaped)
  • Unsanitized path flow identified
Vulnerabilities
None known

Js Css Include Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Js Css Include Manager Release Timeline

v1.4.4Current
v1.4.3
v1.4.2
v1.4.1
v1.4
v1.3.3.1
v1.3.3
v1.3.2
v1.3.1.1
v1.3.1
v1.3
v1.2.1
v1.2
v1.1
Code Analysis
Analyzed Mar 16, 2026

Js Css Include Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
68
23 escaped
Nonce Checks
4
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

25% escaped91 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

5 flows1 with unsanitized paths
jcim_get_load_header (inc\class-manager.php:243)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Js Css Include Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 30
actionplugins_loadedinc\class-config.php:10
actionplugins_loadedinc\class-config.php:11
actioninitinc\class-config.php:12
actioninitinc\class-config.php:13
actioninitinc\class-config.php:14
actioninitinc\class-config.php:15
actioninitinc\class-config.php:16
actionwp_loadedinc\class-data.php:11
actionadmin_initinc\class-data.php:23
actionadmin_initinc\class-data.php:27
actioninitinc\class-manager.php:14
actioninitinc\class-manager.php:15
actionnetwork_admin_menuinc\class-manager.php:66
actionnetwork_admin_noticesinc\class-manager.php:67
actionadmin_menuinc\class-manager.php:72
actionadmin_noticesinc\class-manager.php:73
actionadmin_print_scriptsinc\class-manager.php:77
filteradmin_footer_textinc\class-manager.php:178
actionwp_loadedinc\class-plugin-info.php:16
actionnetwork_admin_noticesinc\class-plugin-info.php:34
actionadmin_noticesinc\class-plugin-info.php:38
actionadmin_initinc\class-plugin-info.php:42
actionadmin_initinc\class-plugin-info.php:43
actionadmin_print_scriptsinc\class-plugin-info.php:51
actionplugins_loadedjs-css-include-manager.php:61
actionwp_loadedjs-css-include-manager.php:69
actionadmin_enqueue_scriptsjs-css-include-manager.php:231
actionadmin_footerjs-css-include-manager.php:232
actionwp_enqueue_scriptsjs-css-include-manager.php:236
actionget_footerjs-css-include-manager.php:237
Maintenance & Trust

Js Css Include Manager Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedSep 24, 2015
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

Js Css Include Manager Developer Profile

gqevu6bsiz

12 plugins · 47K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
183 days
View full developer profile
Detection Fingerprints

How We Detect Js Css Include Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/js-css-include-manager/css/admin.css/wp-content/plugins/js-css-include-manager/css/front.css/wp-content/plugins/js-css-include-manager/js/admin.js/wp-content/plugins/js-css-include-manager/js/front.js
Script Paths
/wp-content/plugins/js-css-include-manager/js/admin.js/wp-content/plugins/js-css-include-manager/js/front.js
Version Parameters
js-css-include-manager/css/admin.css?ver=js-css-include-manager/css/front.css?ver=js-css-include-manager/js/admin.js?ver=js-css-include-manager/js/front.js?ver=

HTML / DOM Fingerprints

CSS Classes
condition_desccondition_add_desc
Data Attributes
data-jcim
FAQ

Frequently Asked Questions about Js Css Include Manager