Live CSS Preview Security & Risk Analysis

wordpress.org/plugins/live-css-preview

Live front-end and Customizer CSS editing powered by native WordPress Additional CSS storage.

300 active installs v2.2.3 PHP 7.4+ WP 5.8+ Updated Apr 6, 2026
csscustomizereditor
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 4, 2025
Safety Verdict

Is Live CSS Preview Safe to Use in 2026?

Generally Safe

Score 99/100

Live CSS Preview has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 4, 2025Updated 5mo ago
Risk Assessment

The 'live-css-preview' plugin v2.1.6 exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices, with all SQL queries utilizing prepared statements, all output being properly escaped, and a complete absence of dangerous functions or file operations. The presence of nonce and capability checks on its single AJAX entry point further reinforces this good practice. The taint analysis shows no identified flows, indicating no obvious vulnerabilities in that area.

However, a significant concern arises from the vulnerability history. The plugin has one known medium-severity CVE, specifically related to Missing Authorization, which is now reported as patched. While it's positive that the CVE is not currently unpatched, the presence of past authorization issues suggests a potential recurring theme. The fact that there's only one past CVE and it's medium severity isn't alarming in isolation, but coupled with the lack of any other identified weaknesses in the code analysis, it highlights that past vulnerabilities may have existed or been introduced due to authorization logic, which can be complex to implement securely.

In conclusion, the plugin is generally well-secured by its current code. The strengths lie in its robust handling of sensitive operations like database queries and output. The primary weakness is the historical existence of a medium-severity authorization vulnerability, which warrants continued vigilance even though it is reportedly patched. Overall, it presents a low immediate risk, but ongoing monitoring for authorization-related issues would be prudent.

Key Concerns

  • Past medium severity CVE (Missing Authorization)
Vulnerabilities
1 published

Live CSS Preview Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-12354medium · 4.3Missing Authorization

Live CSS Preview <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Settings Update

Dec 4, 2025 Patched in 2.1.5 (61d)
Version History

Live CSS Preview Release Timeline

v2.2.3Current
v2.2.2
v2.1.7
v2.1.6
v2.1.5
v2.1.21 CVE
v2.1.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Live CSS Preview Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
19 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped19 total outputs
Attack Surface

Live CSS Preview Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_frontend_savelive-css-preview.php:37
WordPress Hooks 8
actioncustomize_registerlive-css-preview.php:32
actioncustomize_controls_enqueue_scriptslive-css-preview.php:33
actionwp_headlive-css-preview.php:35
actioninitlive-css-preview.php:39
actionwp_enqueue_scriptslive-css-preview.php:47
actionwp_enqueue_scriptslive-css-preview.php:48
actionadmin_bar_menulive-css-preview.php:50
actionwp_footerlive-css-preview.php:80
Maintenance & Trust

Live CSS Preview Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedApr 6, 2026
PHP min version7.4
Downloads9K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

Live CSS Preview Developer Profile

Dojo Digital

3 plugins · 30K total installs

81
trust score
Avg Security Score
90/100
Avg Patch Time
61 days
View full developer profile
Detection Fingerprints

How We Detect Live CSS Preview

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/live-css-preview/assets/css/frontend.css/wp-content/plugins/live-css-preview/assets/css/jquery-ui.css/wp-content/plugins/live-css-preview/assets/js/ace/ace.js/wp-content/plugins/live-css-preview/assets/js/ace/mode-css.js/wp-content/plugins/live-css-preview/assets/js/ace/worker-css.js/wp-content/plugins/live-css-preview/assets/js/ace/theme-monokai.js/wp-content/plugins/live-css-preview/assets/js/frontend.js/wp-content/plugins/live-css-preview/assets/js/customizer.js
Script Paths
/wp-content/plugins/live-css-preview/assets/js/ace/ace.js/wp-content/plugins/live-css-preview/assets/js/ace/mode-css.js/wp-content/plugins/live-css-preview/assets/js/ace/worker-css.js/wp-content/plugins/live-css-preview/assets/js/ace/theme-monokai.js/wp-content/plugins/live-css-preview/assets/js/frontend.js/wp-content/plugins/live-css-preview/assets/js/customizer.js
Version Parameters
live-css-preview/assets/css/frontend.css?ver=live-css-preview/assets/css/jquery-ui.css?ver=live-css-preview/assets/js/ace/ace.js?ver=live-css-preview/assets/js/ace/mode-css.js?ver=live-css-preview/assets/js/ace/worker-css.js?ver=live-css-preview/assets/js/ace/theme-monokai.js?ver=live-css-preview/assets/js/frontend.js?ver=live-css-preview/assets/js/customizer.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-customize-editor
JS Globals
ajaxurllivecss_noncedojodigital_live_css
FAQ

Frequently Asked Questions about Live CSS Preview