
Legacy Jetpack Custom CSS Editor Security & Risk Analysis
wordpress.org/plugins/legacy-jetpack-custom-css-editorThis plugin re-adds the full page admin Custom CSS editor to Jetpack.
Is Legacy Jetpack Custom CSS Editor Safe to Use in 2026?
Generally Safe
Score 85/100Legacy Jetpack Custom CSS Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The legacy-jetpack-custom-css-editor plugin version 0.9 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection risks due to prepared statements, and minimal external requests are positive indicators. Furthermore, the plugin demonstrates good practices with a high percentage of properly escaped output and the presence of nonce and capability checks on its entry points. The vulnerability history is also entirely clean, with no known CVEs, which suggests a well-maintained or less targeted plugin.
Despite these strengths, the analysis does reveal a single AJAX handler as the sole entry point. While it has an apparent authentication check, the static analysis does not detail the specifics of this check. The total lack of taint analysis results could be due to the limited complexity of the plugin or limitations in the analysis tool's scope for this specific plugin. However, it means there's no specific insight into potential data flow vulnerabilities. Overall, the plugin appears relatively secure, but the reliance on a single AJAX handler warrants careful review of its authentication mechanism.
Legacy Jetpack Custom CSS Editor Security Vulnerabilities
Legacy Jetpack Custom CSS Editor Code Analysis
Output Escaping
Legacy Jetpack Custom CSS Editor Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Legacy Jetpack Custom CSS Editor Maintenance & Trust
Maintenance Signals
Community Trust
Legacy Jetpack Custom CSS Editor Alternatives
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
Insert Headers And Footers
wp-headers-and-footers
Include inline javascript, stylesheets, CSS code or anything you want in Header and Footer areas of your WordPress with ease.
Jetpack Protect
jetpack-protect
Free daily vulnerability scans & WordPress security, powered by WPScan (an Automattic brand) and its 60,000+ vulnerability database. No setup needed!
Simple Custom CSS Plugin
simple-custom-css
Add Custom CSS to your WordPress site without any hassles.
Simple CSS
simple-css
Add CSS to your website through an admin editor, the Customizer or a metabox for page/post specific CSS.
Legacy Jetpack Custom CSS Editor Developer Profile
16 plugins · 16K total installs
How We Detect Legacy Jetpack Custom CSS Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/legacy-jetpack-custom-css-editor/use-codemirror.js/wp-content/plugins/legacy-jetpack-custom-css-editor/no-jetpack.js/wp-content/plugins/legacy-jetpack-custom-css-editor/use-codemirror.js/wp-content/plugins/legacy-jetpack-custom-css-editor/no-jetpack.jslegacy-jetpack-custom-css-editor/use-codemirror.js?ver=0.1-devHTML / DOM Fingerprints
id="legacy-form"name="css"name="jetpack_custom_css[preprocessor]"name="jetpack_custom_css[replace]"name="jetpack_custom_css[content_width]"