Mimo Colors Security & Risk Analysis

wordpress.org/plugins/mimo-colors

Color easily any element in your site, no coding required, you only need to know the class or id of the html element you need to apply colors.

10 active installs v1.0 PHP + WP 4.3+ Updated Unknown
color-customizercolorscustomextra-colorsstyle
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mimo Colors Safe to Use in 2026?

Generally Safe

Score 100/100

Mimo Colors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The mimo-colors v1.0 plugin exhibits a generally good security posture with no recorded vulnerabilities or critical taint analysis findings. The static analysis reveals a small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, suggesting limited potential entry points for attackers. Furthermore, the plugin demonstrates an effort towards secure coding practices, with a significant percentage of SQL queries using prepared statements and a notable number of nonce and capability checks.

However, concerns arise from the presence of two dangerous functions: 'unserialize' and 'create_function'. The use of 'unserialize' is particularly risky as it can lead to Remote Code Execution (RCE) vulnerabilities if the data being unserialized originates from an untrusted source. While the current taint analysis shows no unsanitized paths, this remains a significant potential vector for attack. Additionally, only 63% of output escaping is properly implemented, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities in the remaining outputs.

Given the absence of historical vulnerabilities, the plugin has a clean track record, which is a positive sign. Nevertheless, the identified code signals, specifically the use of 'unserialize' and the incomplete output escaping, present inherent risks that cannot be overlooked. A balanced conclusion is that while the plugin has a low apparent risk due to its limited attack surface and clean history, the presence of dangerous functions and less than perfect output escaping warrants careful monitoring and potential remediation.

Key Concerns

  • Presence of 'unserialize' function
  • Presence of 'create_function' function
  • Unescaped output identified
Vulnerabilities
None known

Mimo Colors Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mimo Colors Code Analysis

Dangerous Functions
2
Raw SQL Queries
1
3 prepared
Unescaped Output
42
72 escaped
Nonce Checks
6
Capability Checks
4
File Operations
3
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$datetime = unserialize( $args['value'] );admin\includes\CMB2\includes\CMB2_Types.php:583
create_functionadd_filter( 'cml_my_translations', create_function( "$groups, $plugin_name_human_format","includes\language.php:47

SQL Query Safety

75% prepared4 total queries

Output Escaping

63% escaped114 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
settings_import (admin\class-mimo-colors-admin.php:410)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Mimo Colors Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 42
actionadmin_enqueue_scriptsadmin\class-mimo-colors-admin.php:69
actionadmin_enqueue_scriptsadmin\class-mimo-colors-admin.php:70
actionadmin_head-index.phpadmin\class-mimo-colors-admin.php:72
actionadmin_menuadmin\class-mimo-colors-admin.php:76
actionadmin_menuadmin\class-mimo-colors-admin.php:78
actionadmin_initadmin\class-mimo-colors-admin.php:89
actionadmin_initadmin\class-mimo-colors-admin.php:91
filterwp_contextual_help_docs_diradmin\class-mimo-colors-admin.php:99
filterwp_contextual_help_docs_urladmin\class-mimo-colors-admin.php:100
actioninitadmin\class-mimo-colors-admin.php:104
filterpointerplus_listadmin\class-mimo-colors-admin.php:135
filterget_post_metadataadmin\includes\CMB2\includes\CMB2_Ajax.php:114
filterupdate_post_metadataadmin\includes\CMB2\includes\CMB2_Ajax.php:117
filtercmb2_show_onadmin\includes\CMB2\includes\CMB2_hookup.php:66
actionadd_meta_boxesadmin\includes\CMB2\includes\CMB2_hookup.php:79
actionadd_attachmentadmin\includes\CMB2\includes\CMB2_hookup.php:80
actionedit_attachmentadmin\includes\CMB2\includes\CMB2_hookup.php:81
actionsave_postadmin\includes\CMB2\includes\CMB2_hookup.php:82
actionshow_user_profileadmin\includes\CMB2\includes\CMB2_hookup.php:107
actionedit_user_profileadmin\includes\CMB2\includes\CMB2_hookup.php:108
actionuser_new_formadmin\includes\CMB2\includes\CMB2_hookup.php:109
actionpersonal_options_updateadmin\includes\CMB2\includes\CMB2_hookup.php:111
actionedit_user_profile_updateadmin\includes\CMB2\includes\CMB2_hookup.php:112
actionuser_registeradmin\includes\CMB2\includes\CMB2_hookup.php:113
actioninitadmin\includes\CMB2\init.php:72
actioncurrent_screenadmin\includes\PointerPlus\class-pointerplus.php:25
actionadmin_enqueue_scriptsadmin\includes\PointerPlus\class-pointerplus.php:117
actionadmin_noticesadmin\includes\PointerPlus\class-pointerplus.php:121
actioncurrent_screenadmin\includes\PointerPlus\class-pointerplus.php:145
actionplugins_loadedadmin\includes\PointerPlus\pointerplus.php:36
actionadmin_noticesadmin\includes\WP-Admin-Notice\WP_Admin_Notice.php:10
actionnetwork_admin_noticesadmin\includes\WP-Admin-Notice\WP_Admin_Notice.php:11
actioninitadmin\includes\WP-Contextual-Help\wp-contextual-help.php:141
filtercml_my_translationsincludes\language.php:47
actionplugins_loadedmimo-colors.php:59
actionplugins_loadedmimo-colors.php:72
actioninitpublic\class-mimo-colors.php:96
actionwpmu_new_blogpublic\class-mimo-colors.php:99
actionwp_enqueue_scriptspublic\class-mimo-colors.php:105
actionwp_enqueue_scriptspublic\class-mimo-colors.php:106
actionwp_enqueue_scriptspublic\class-mimo-colors.php:107
actionwp_enqueue_scriptspublic\class-mimo-colors.php:108
Maintenance & Trust

Mimo Colors Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Mimo Colors Developer Profile

mimo

8 plugins · 910 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mimo Colors

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mimo-colors/admin/css/mimo-colors-admin.css/wp-content/plugins/mimo-colors/admin/js/mimo-colors-admin.js/wp-content/plugins/mimo-colors/public/css/mimo-colors.css/wp-content/plugins/mimo-colors/public/js/mimo-colors.js
Version Parameters
mimo-colors/admin/css/mimo-colors-admin.css?ver=mimo-colors/admin/js/mimo-colors-admin.js?ver=mimo-colors/public/css/mimo-colors.css?ver=mimo-colors/public/js/mimo-colors.js?ver=

HTML / DOM Fingerprints

CSS Classes
mimo-colors-admin-wrap
HTML Comments
<!-- Mimo Colors. --><!-- Plugin class. This class should ideally be used to work with the * administrative side of the WordPress site. * --><!-- If you're interested in introducing public-facing * functionality, then refer to `class-mimo-colors.php` * -->
FAQ

Frequently Asked Questions about Mimo Colors