
Kento Splash Screen Security & Risk Analysis
wordpress.org/plugins/kento-splash-screenSplash screen box for first time visit or new visitors
Is Kento Splash Screen Safe to Use in 2026?
Use With Caution
Score 63/100Kento Splash Screen has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "kento-splash-screen" plugin, version 1.4, exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no external HTTP requests or file operations, significant concerns remain. A critical finding is the complete lack of output escaping, meaning all 29 outputs are potentially vulnerable to cross-site scripting (XSS) attacks. Additionally, the plugin has a known unpatched medium severity CVE from August 2025, indicating a recent and ongoing security risk. The presence of a taint flow with unsanitized paths, even if not currently categorized as critical or high, warrants attention as it suggests potential vulnerabilities if exploited correctly. The absence of nonce and capability checks on its single shortcode entry point also increases its attack surface, though it has no direct AJAX or REST API entry points.
Key Concerns
- Unpatched CVE
- No output escaping
- Taint flow with unsanitized paths
- No nonce check on shortcode
- No capability check on shortcode
Kento Splash Screen Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Kento Splash Screen <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Kento Splash Screen Code Analysis
Output Escaping
Data Flow Analysis
Kento Splash Screen Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Kento Splash Screen Maintenance & Trust
Maintenance Signals
Community Trust
Kento Splash Screen Alternatives
N360 | Splash Screen
n360-splash-screen
A responsive fade-in-out splash screen and landing page for your existing theme.
AweSplash – Just Splash Page
awesplash
A splash page for your WordPress site.
ABtesting.ai – Landing Page Optimization
abtesting-ai
Automate your landing page A/B testing by using AI.
W8ing
w8ing
A basic waiting/landing page plugin for Wordpress
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
Kento Splash Screen Developer Profile
20 plugins · 600 total installs
How We Detect Kento Splash Screen
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kento-splash-screen/css/style.css/wp-content/plugins/kento-splash-screen/css/responsive.css/wp-content/plugins/kento-splash-screen/js/kento-splash-screen-ajax.js/wp-content/plugins/kento-splash-screen/js/kento-splash-screen-ajax.jskento-splash-screen/css/style.css?ver=kento-splash-screen/css/responsive.css?ver=kento-splash-screen/js/kento-splash-screen-ajax.js?ver=HTML / DOM Fingerprints
kento-splash-screenid="kento-splash-screen-black"id="testing"id="kento-splash-screen"<div id="kento-splash-screen-black" style="display:none;"><div id="testing"></div></div><div class="kento-splash-screen" style="