
Pastacode Security & Risk Analysis
wordpress.org/plugins/pastacodeUse Pastacode to add code into your posts with the awesome PrismJs coloration library. So, past'a code!
Is Pastacode Safe to Use in 2026?
Generally Safe
Score 100/100Pastacode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'pastacode' plugin v3.0.1 exhibits a mixed security posture. While it has no recorded historical vulnerabilities and a high percentage of properly escaped outputs, significant concerns arise from its attack surface. Two AJAX handlers are exposed without authentication checks, presenting a direct entry point for potential malicious activity. Additionally, the plugin performs SQL queries without using prepared statements, increasing the risk of SQL injection vulnerabilities. The lack of taint analysis data is noted, but it does not negate the explicit risks identified in the code signals. Overall, the plugin's strengths lie in its clean vulnerability history and good output escaping practices, but the unprotected entry points and un-prepared SQL queries are substantial weaknesses that require immediate attention.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
Pastacode Security Vulnerabilities
Pastacode Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Pastacode Attack Surface
AJAX Handlers 2
REST API Routes 1
Shortcodes 1
WordPress Hooks 45
Maintenance & Trust
Pastacode Maintenance & Trust
Maintenance Signals
Community Trust
Pastacode Alternatives
SyntaxHighlighter Evolved
syntaxhighlighter
Easily post syntax-highlighted code to your site without having to modify the code at all. As seen on WordPress.com.
Code Block Pro – Beautiful Syntax Highlighting
code-block-pro
Code highlighting powered by the VS Code engine. Performance focused. No bloat.
Highlighting Code Block
highlighting-code-block
Add code block with syntax highlighting using prism.js. (Available for Gutenberg and Classic Editor)
Syntax-highlighting Code Block (with Server-side Rendering)
syntax-highlighting-code-block
Extending the Code block with syntax highlighting rendered on the server, thus being AMP-compatible and having faster frontend performance.
WP SyntaxHighlighter
wp-syntaxhighlighter
This plugin is code syntax highlighter based on SyntaxHighlighter ver. 3.0.83 and 2.1.382.
Pastacode Developer Profile
8 plugins · 9K total installs
How We Detect Pastacode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pastacode/js/prism.js/wp-content/plugins/pastacode/plugins/line-highlight/prism-line-highlight.min.js/wp-content/plugins/pastacode/plugins/normalize-whitespace/prism-normalize-whitespace.min.js/wp-content/plugins/pastacode/plugins/line-numbers/prism-line-numbers.min.js/wp-content/plugins/pastacode/plugins/show-invisibles/prism-show-invisibles.min.js/wp-content/plugins/pastacode/css/prism.css/wp-content/plugins/pastacode/plugins/line-highlight/prism-line-highlight.css/wp-content/plugins/pastacode/plugins/line-numbers/prism-line-numbers.css+3 morepastacode/js/prism.js?ver=pastacode/plugins/line-highlight/prism-line-highlightpastacode/plugins/normalize-whitespace/prism-normalize-whitespacepastacode/plugins/line-numbers/prism-line-numberspastacode/plugins/show-invisibles/prism-show-invisiblespastacode/css/prism.css?ver=pastacode/plugins/line-highlight/prism-line-highlight.css?ver=pastacode/plugins/line-numbers/prism-line-numbers.css?ver=pastacode/plugins/show-invisibles/prism-show-invisibles.css?ver=pastacode/plugins/treeview/prism-treeviewpastacode/plugins/treeview/prism-treeview.js?ver=HTML / DOM Fingerprints
code-embed-infoscode-embed-namecode-embed-rawcode-embed-wrappercode-embed-precode-embed-codedata-startdata-line-offset<div class="code-embed-wrapper"><pre class="language- code-embed-pre" data-start="