
Page Loading Security & Risk Analysis
wordpress.org/plugins/page-loadingAdd a CSS3 effect to your blog while loading pages. 給你的部落格增加一個帶有CSS3效果的頁面載入動畫
Is Page Loading Safe to Use in 2026?
Generally Safe
Score 85/100Page Loading has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "page-loading" v1.0.5 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the analysis indicates no dangerous functions, no raw SQL queries (all use prepared statements), no file operations, and no external HTTP requests, all of which are positive indicators. The plugin also has no recorded vulnerabilities, suggesting a clean security history.
However, there are notable areas of concern. The most significant is the complete lack of output escaping. With one output detected and none properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is ever rendered directly to the browser. Additionally, the absence of nonce checks and capability checks, while perhaps less critical given the limited attack surface, still represent a deviation from best practices for securing WordPress functionality, especially if the plugin's functionality were to expand in the future. The lack of taint analysis data is also a limitation, making it impossible to assess risks related to data flow vulnerabilities.
In conclusion, while the "page-loading" plugin starts with a very small attack surface and avoids common pitfalls like raw SQL and dangerous functions, the unescaped output presents a significant and actionable risk. The absence of security checks like nonces and capabilities, while less critical now, should be addressed proactively. The plugin's strength lies in its minimal entry points, but its weakness is the lack of output sanitation, which could lead to critical vulnerabilities.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
Page Loading Security Vulnerabilities
Page Loading Code Analysis
Output Escaping
Page Loading Attack Surface
WordPress Hooks 3
Maintenance & Trust
Page Loading Maintenance & Trust
Maintenance Signals
Community Trust
Page Loading Alternatives
LoftLoader
loftloader
An easy to use plugin to add an animated preloader to your website with fully customisations.
Loading Page with Loading Screen
loading-page
Loading Page with Loading Screen plugin performs a pre-loading of images on your website and displays a loading progress screen with percentage of com …
Page Loader
page-loader
Page Loader is a free Wordpress plugin to show a loader animation while page is being loaded.
Page Animations And Transitions
page-animations-and-transitions
Page Animations And Transition is provide multiple Animation effect to your WordPress site. Show your page with stylish transition.
Preloader Awesome – Page Loading Animation with Spinner & Gif
preloader-awesome
Preloader Awesome help You to create page loading animation WordPress with spinner or You can upload Your own GIF.
Page Loading Developer Profile
24 plugins · 2K total installs
How We Detect Page Loading
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-loading/style.cssHTML / DOM Fingerprints
circlecircle1