
Just Writing Security & Risk Analysis
wordpress.org/plugins/just-writingAdds buttons and features to the Distraction Free Writing Mode for all kinds of extra functions.
Is Just Writing Safe to Use in 2026?
Generally Safe
Score 92/100Just Writing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'just-writing' v4.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history suggest a commitment to security by the developers. Furthermore, the analysis reveals a commendable lack of critical or high-severity taint flows, a small attack surface with no unprotected entry points, and a reasonable number of capability checks for its operations. This indicates that for its core functionality, the plugin appears to be designed with security in mind.
However, several areas present significant concerns that could lead to vulnerabilities. The most prominent issue is the complete lack of prepared statements for all eight SQL queries. This is a major security risk, as it leaves the plugin highly susceptible to SQL injection attacks. Additionally, the extremely low rate of proper output escaping (4% out of 597 outputs) is deeply concerning. Unescaped output can lead to various client-side vulnerabilities, including Cross-Site Scripting (XSS). The presence of bundled libraries, while not explicitly stated as outdated, always carries a potential risk if not regularly maintained.
In conclusion, while 'just-writing' v4.0 benefits from a clean vulnerability history and a limited attack surface, the critical issues with SQL query preparation and output escaping represent significant security weaknesses that must be addressed. These findings overshadow the otherwise positive aspects of the analysis, demanding immediate attention from developers to mitigate potential exploitation.
Key Concerns
- All SQL queries lack prepared statements
- Very low percentage of properly escaped output
- Bundled libraries present (potential for outdated components)
Just Writing Security Vulnerabilities
Just Writing Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Just Writing Attack Surface
WordPress Hooks 37
Maintenance & Trust
Just Writing Maintenance & Trust
Maintenance Signals
Community Trust
Just Writing Alternatives
No alternatives data available yet.
Just Writing Developer Profile
34 plugins · 8K total installs
How We Detect Just Writing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/just-writing/3.5/just-writing-editor.3.5.css/wp-content/plugins/just-writing/3.5/just-writing-editor.3.5.js/wp-content/plugins/just-writing/3.5/just-writing.3.5.css/wp-content/plugins/just-writing/3.5/just-writing.3.5.js/wp-content/plugins/just-writing/3.9/just-writing-editor.3.9.css/wp-content/plugins/just-writing/3.9/just-writing-editor.3.9.js/wp-content/plugins/just-writing/3.9/just-writing.3.9.css/wp-content/plugins/just-writing/3.9/just-writing.3.9.js+17 more/wp-content/plugins/just-writing/3.5/just-writing-editor.3.5.js/wp-content/plugins/just-writing/3.5/just-writing.3.5.js/wp-content/plugins/just-writing/3.9/just-writing-editor.3.9.js/wp-content/plugins/just-writing/3.9/just-writing.3.9.js/wp-content/plugins/just-writing/4.1/just-writing-editor.4.1.js/wp-content/plugins/just-writing/4.1/just-writing.4.1.js+6 morever=4.0ver=3.5ver=3.9ver=4.1ver=4.3ver=4.5ver=5.7HTML / DOM Fingerprints
<!-- Start Just Writing --><!-- End Just Writing -->data-just-writing-enableddata-just-writing-bolddata-just-writing-italicsdata-just-writing-uldata-just-writing-nldata-just-writing-quotes+19 morewindow.JustWriting_EditPost_Optionswindow.JustWriting_EditPost_FormatButtonswindow.JustWriting_EditPost_Buttonswindow.JustWriting_EditPostwindow.JustWriting_Editor_Optionswindow.JustWriting_Editor_FormatButtons+2 more