LH Cookieless Domain Security & Risk Analysis

wordpress.org/plugins/lh-cookieless-domain

Filters the css and script source attribute and moves their domain to one of your choosing

0 active installs v1.02 PHP + WP + Updated Unknown
cdncookiescssscriptssubdomain
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LH Cookieless Domain Safe to Use in 2026?

Generally Safe

Score 100/100

LH Cookieless Domain has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "lh-cookieless-domain" plugin v1.02 exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and zero recorded vulnerabilities in its history is a significant positive indicator, suggesting a well-maintained and secure plugin. Furthermore, the code analysis reveals an empty attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, all of which are critical entry points for potential attacks. The plugin also adheres to good practices by utilizing prepared statements for all SQL queries and includes both nonce and capability checks.

However, there is a notable concern regarding output escaping. With 38% of outputs properly escaped, a significant portion (62%) may be vulnerable to cross-site scripting (XSS) attacks. While no critical or high-severity taint flows were identified, the lack of thorough output escaping leaves room for potential client-side vulnerabilities that could be exploited. The plugin's strengths lie in its minimal attack surface and secure data handling for SQL, but the unescaped output presents a clear weakness that requires attention.

Key Concerns

  • Output escaping is insufficient
Vulnerabilities
None known

LH Cookieless Domain Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LH Cookieless Domain Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
3 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped8 total outputs
Attack Surface

LH Cookieless Domain Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterscript_loader_srclh-cookieless-domain.php:239
filterstyle_loader_srclh-cookieless-domain.php:241
filterwp_get_attachment_urllh-cookieless-domain.php:245
actionnetwork_admin_menulh-cookieless-domain.php:252
actionadmin_menulh-cookieless-domain.php:254
actionget_headerlh-cookieless-domain.php:259
actionplugins_loadedlh-cookieless-domain.php:285
Maintenance & Trust

LH Cookieless Domain Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LH Cookieless Domain Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH Cookieless Domain

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lh-cookieless-domain/lh-cookieless-domain.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about LH Cookieless Domain