
Just Animate – For Classic Editor Security & Risk Analysis
wordpress.org/plugins/just-animateJust Animate - Easily animate text or images in the WordPress classic editor.
Is Just Animate – For Classic Editor Safe to Use in 2026?
Generally Safe
Score 85/100Just Animate – For Classic Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis, "just-animate" v1.0 presents a generally strong security posture with no identified critical or high-severity vulnerabilities in the code. The absence of AJAX handlers, REST API routes, shortcodes, cron events, dangerous functions, and raw SQL queries significantly limits the potential attack surface. The use of prepared statements for all SQL queries is a commendable practice. The plugin also implements capability checks, which is a positive sign for access control.
However, a notable concern arises from the output escaping results, where 100% of outputs are not properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted to the browser without sanitization. While taint analysis shows no flows, this is likely due to the limited attack surface analyzed and doesn't negate the risk from unescaped output. The lack of vulnerability history for this plugin is also positive, suggesting a history of secure development, but it doesn't excuse the identified output escaping issue.
In conclusion, "just-animate" v1.0 demonstrates good secure coding practices by minimizing entry points and avoiding common pitfalls like raw SQL. The primary and most significant weakness identified is the complete lack of output escaping, which represents a tangible risk of XSS. While the attack surface is minimal and there are no known past vulnerabilities, this single flaw requires immediate attention to ensure user data is protected.
Key Concerns
- All outputs are unescaped
Just Animate – For Classic Editor Security Vulnerabilities
Just Animate – For Classic Editor Release Timeline
Just Animate – For Classic Editor Code Analysis
Output Escaping
Just Animate – For Classic Editor Attack Surface
WordPress Hooks 8
Maintenance & Trust
Just Animate – For Classic Editor Maintenance & Trust
Maintenance Signals
Community Trust
Just Animate – For Classic Editor Alternatives
Animated Text Block – Add Typing and Looping Text Effects
animated-text-block
Animated Text Block – Add dynamic, customizable text animations to your WordPress site with ease.
AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations
animategl
CSS & WebGL Animations for Elementor & Gutenberg Blocks Animations, animations from CSS class, scroll animations, lock to scrollbar.
Animated Text Widget for Elementor
animated-text-widget-for-elementor
Add an animated typing effect to your Elementor pages with customizable text strings, speed, delay, and styling options.
Rotating Words For WPBakery Page Builder
rotating-words-for-visual-composer
Add rotating animated words to WPBakery-built pages. Create eye-catching headlines and dynamic text with customizable animations, speed, and styling.
FlexiWords
flexiwords
Create eye-catching text animations with rotating words. Combine fixed and dynamic texts with customizable colors, fonts, and animation settings.
Just Animate – For Classic Editor Developer Profile
1 plugin · 10 total installs
How We Detect Just Animate – For Classic Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/just-animate/js/animate.js/wp-content/plugins/just-animate/css/admin-style.css/wp-content/plugins/just-animate/css/editor-style.css/wp-content/plugins/just-animate/css/style.css/wp-content/plugins/just-animate/js/onscroll.js/wp-content/plugins/just-animate/js/animate.js/wp-content/plugins/just-animate/js/onscroll.jsjust-animate/js/animate.js?ver=just-animate/css/admin-style.css?ver=just-animate/css/editor-style.css?ver=just-animate/css/style.css?ver=just-animate/js/onscroll.js?ver=