NextGenThemes jsDelivr CDN Security & Risk Analysis

wordpress.org/plugins/nextgenthemes-jsdelivr-this

Free CDN for for all assets from wordpress.org Github and NPM.

400 active installs v1.3.3 PHP 8.0+ WP 6.2.0+ Updated Oct 12, 2025
cdnjavascriptjsjsdelivrnextgenthemes
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NextGenThemes jsDelivr CDN Safe to Use in 2026?

Generally Safe

Score 100/100

NextGenThemes jsDelivr CDN has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

Based on the provided analysis, the "nextgenthemes-jsdelivr-this" plugin version 1.3.3 presents a strong security posture with no identified vulnerabilities in its history or critical issues flagged by static analysis. The absence of known CVEs and a clean vulnerability history indicate a well-maintained and secure plugin. Furthermore, the code analysis reveals a minimal attack surface with zero entry points, zero AJAX handlers, zero REST API routes, and zero shortcodes. The code also demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped output, reducing the risk of injection and cross-site scripting vulnerabilities. The lack of dangerous functions and critical taint flows is also a positive sign.

However, there are a few areas that, while not currently indicating vulnerabilities, warrant attention for future development or auditing. The plugin has zero nonce checks and zero capability checks, meaning that any potential future entry points, if introduced, would be unprotected by standard WordPress security mechanisms. While the current attack surface is zero, the absence of these checks could become a significant risk if functionality is added without proper authorization. Additionally, the presence of file operations and external HTTP requests, while not flagged as problematic in this analysis, are always potential vectors for vulnerabilities if not handled with extreme care and proper sanitization.

Key Concerns

  • No Nonce Checks Present
  • No Capability Checks Present
  • File Operations Present
  • External HTTP Requests Present
Vulnerabilities
None known

NextGenThemes jsDelivr CDN Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

NextGenThemes jsDelivr CDN Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
2
Bundled Libraries
0

Output Escaping

94% escaped17 total outputs
Attack Surface

NextGenThemes jsDelivr CDN Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionafter_setup_themenextgenthemes-jsdelivr-this.php:23
actioninitnextgenthemes-jsdelivr-this.php:34
filterwp_script_attributesnextgenthemes-jsdelivr-this.php:40
filterstyle_loader_tagnextgenthemes-jsdelivr-this.php:41
actionadmin_bar_menunextgenthemes-jsdelivr-this.php:43
filterinitnextgenthemes-jsdelivr-this.php:45
actionwp_enqueue_scriptsnextgenthemes-jsdelivr-this.php:46
actionadmin_enqueue_scriptsnextgenthemes-jsdelivr-this.php:47
actionadmin_footernextgenthemes-jsdelivr-this.php:49
actionwp_footernextgenthemes-jsdelivr-this.php:50
filterplugin_row_metanextgenthemes-jsdelivr-this.php:52
Maintenance & Trust

NextGenThemes jsDelivr CDN Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 12, 2025
PHP min version8.0
Downloads18K

Community Trust

Rating100/100
Number of ratings6
Active installs400
Developer Profile

NextGenThemes jsDelivr CDN Developer Profile

Nico

7 plugins · 21K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NextGenThemes jsDelivr CDN

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nextgenthemes-jsdelivr-this/dialog.css/wp-content/plugins/nextgenthemes-jsdelivr-this/dialog.js
Script Paths
/wp-content/plugins/nextgenthemes-jsdelivr-this/dialog.js
Version Parameters
/wp-content/plugins/nextgenthemes-jsdelivr-this/dialog.css?ver=/wp-content/plugins/nextgenthemes-jsdelivr-this/dialog.js?ver=

HTML / DOM Fingerprints

CSS Classes
ngt-jsdelivr-dialogngt-jsdelivr-dialog__headermedia-modal-closemedia-modal-iconscreen-reader-text
Data Attributes
data-wp-el="editor"data-wp-element="editor"
JS Globals
window.wpApiSettings
FAQ

Frequently Asked Questions about NextGenThemes jsDelivr CDN