
Plum Code Box Security & Risk Analysis
wordpress.org/plugins/plum-code-boxPlum Code Box makes it easy to insert and manage code blocks using the Chili javascript syntax highlighter.
Is Plum Code Box Safe to Use in 2026?
Generally Safe
Score 85/100Plum Code Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'plum-code-box' version 1.1 exhibits a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests is a positive indicator. Furthermore, the presence of nonce and capability checks, even with a limited attack surface, suggests an awareness of basic security practices. However, a significant concern arises from the complete lack of output escaping on all identified output points. This means that any data processed and displayed by the plugin, if it originates from an untrusted source, could potentially be vulnerable to cross-site scripting (XSS) attacks. The plugin's vulnerability history being entirely clear is a good sign, but it doesn't negate the risks identified in the static analysis. A balanced conclusion would note the lack of complex vulnerabilities and good use of core WordPress security features, but highlight the critical need to address the unescaped output to prevent potential XSS vulnerabilities.
Key Concerns
- All identified outputs are unescaped
Plum Code Box Security Vulnerabilities
Plum Code Box Code Analysis
Output Escaping
Plum Code Box Attack Surface
WordPress Hooks 3
Maintenance & Trust
Plum Code Box Maintenance & Trust
Maintenance Signals
Community Trust
Plum Code Box Alternatives
Code Widget
code-widget
Code widget help to add Short Code, PHP Code, HTML, and Simple Text in widget.
Append extensions on Pages
append-extensions-on-pages
This plugin helps to appends .html or .asp or .htm etc on the wordpress pages when used with permalink.
Code Manager
code-manager
Write, test and deploy PHP, JavaScript, CSS and HTML code blocks from the WordPress dashboard.
ionCube Tester Plus
ioncube-tester-plus
This plugin helps you to determine if the ionCube loaders are installed correctly on your web server. This plugin is sponsored by "Maps Marker Pr …
2MB Autocode
2mb-autocode
This plugin allows you to place predetermined text/html/php at the top or bottom of posts.
Plum Code Box Developer Profile
1 plugin · 20 total installs
How We Detect Plum Code Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plum-code-box/chili/jquery.chili-2.2.js/wp-content/plugins/plum-code-box/chili/recipes.js/wp-content/plugins/plum-code-box/chili/jquery.chili-2.2.js/wp-content/plugins/plum-code-box/chili/recipes.jsplum-code-box/chili/jquery.chili-2.2.js?ver=plum-code-box/chili/recipes.js?ver=HTML / DOM Fingerprints
Plum_Code_BoxPlum_Code_Box_noncePlum_Code_Box_number_of_boxesPlum_Code_Box_code_Plum_Code_Box_display_boxes[codebox