
LH Cookieless Domain Security & Risk Analysis
wordpress.org/plugins/lh-cookieless-domainFilters the css and script source attribute and moves their domain to one of your choosing
Is LH Cookieless Domain Safe to Use in 2026?
Generally Safe
Score 100/100LH Cookieless Domain has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lh-cookieless-domain" plugin v1.02 exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and zero recorded vulnerabilities in its history is a significant positive indicator, suggesting a well-maintained and secure plugin. Furthermore, the code analysis reveals an empty attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, all of which are critical entry points for potential attacks. The plugin also adheres to good practices by utilizing prepared statements for all SQL queries and includes both nonce and capability checks.
However, there is a notable concern regarding output escaping. With 38% of outputs properly escaped, a significant portion (62%) may be vulnerable to cross-site scripting (XSS) attacks. While no critical or high-severity taint flows were identified, the lack of thorough output escaping leaves room for potential client-side vulnerabilities that could be exploited. The plugin's strengths lie in its minimal attack surface and secure data handling for SQL, but the unescaped output presents a clear weakness that requires attention.
Key Concerns
- Output escaping is insufficient
LH Cookieless Domain Security Vulnerabilities
LH Cookieless Domain Code Analysis
Output Escaping
LH Cookieless Domain Attack Surface
WordPress Hooks 7
Maintenance & Trust
LH Cookieless Domain Maintenance & Trust
Maintenance Signals
Community Trust
LH Cookieless Domain Alternatives
WP cdnjs
wp-cdnjs
Integrates easily CSS and JavaScript Libraries hosted by CDNjs.com. Browse, select version and sub-assets to fit your needs.
BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript
searchpro
Automatically boost your PageSpeed score to 90+ for both mobile & desktop and pass Core Web Vitals for WordPress website without any technical skills.
Speed Up – Browser Caching
speed-up-browser-caching
Help browser to cache a local copy of static files and improve page load times.
Remove Emoji CSS and JS
remove-emoji-css-and-js
This is the best plugin to remove Emoji CSS and JS from the website and improve the performance.
Conditionally Load CF7
cf7-conditional-load
Load Contact Form 7 & select CF7-related plugin scripts & styles only where needed.
LH Cookieless Domain Developer Profile
77 plugins · 15K total installs
How We Detect LH Cookieless Domain
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-cookieless-domain/lh-cookieless-domain.php