Pressfore Preloaders Security & Risk Analysis

wordpress.org/plugins/pressfore-preloaders

Best free wordpress preloaders plugin for creating stunning spinners/preloaders which will be displayed while your page is loading.

40 active installs v1.0.2 PHP + WP 3.9.0+ Updated Jan 2, 2018
loadingpostspreloaderwebiste-preloaderwordpress-preloader
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pressfore Preloaders Safe to Use in 2026?

Generally Safe

Score 85/100

Pressfore Preloaders has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'pressfore-preloaders' plugin v1.0.2 exhibits a strong security posture. The absence of any detected dangerous functions, raw SQL queries, file operations, external HTTP requests, and a complete lack of any identified vulnerability history (CVEs) are all positive indicators. The plugin also appears to adhere to good coding practices by properly escaping all outputs and using prepared statements for any SQL interactions, which are essential for preventing common web vulnerabilities.

However, a notable area of concern is the complete absence of any nonce checks or capability checks across its entire attack surface, which is currently reported as zero entry points. While this means there's no immediate risk from these checks being missing, it indicates a potential oversight in the plugin's security architecture. If the plugin were to introduce any new entry points in future versions (AJAX handlers, REST API routes, shortcodes, cron events), the lack of these fundamental security checks could expose it to significant risks like Cross-Site Request Forgery (CSRF) or unauthorized privilege escalation. The taint analysis also reported zero flows, which is positive, but this is in conjunction with an attack surface of zero, making it difficult to fully assess the taint handling capabilities in a real-world scenario.

In conclusion, the plugin is currently secure due to its minimal attack surface and absence of known vulnerabilities. The coding practices observed are commendable. The primary weakness lies in the potential for future vulnerabilities if new entry points are added without implementing essential security measures like nonce and capability checks. For a plugin with zero entry points, it's hard to assign points based on missing checks, but the pattern is a risk.

Vulnerabilities
None known

Pressfore Preloaders Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Pressfore Preloaders Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Pressfore Preloaders Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Pressfore Preloaders Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioncustomize_registerinc\options.php:144
filterpressfore_preloaders_outputinc\render.php:33
actionpressfore_preloaders_printinc\render.php:77
filterbody_classinc\render.php:95
actionwp_enqueue_scriptsinc\render.php:202
actionwp_footerinc\render.php:214
actionwp_enqueue_scriptsinc\setup.php:14
actioncustomize_preview_initinc\setup.php:15
actioncustomize_controls_enqueue_scriptsinc\setup.php:16
filterplugin_row_metainc\setup.php:17
actioncustomize_registerpressfore-preloaders.php:44
actioninitpressfore-preloaders.php:56
Maintenance & Trust

Pressfore Preloaders Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 2, 2018
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Pressfore Preloaders Developer Profile

pressfore

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pressfore Preloaders

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pressfore-preloaders/assets/js/customizer-controls.js/wp-content/plugins/pressfore-preloaders/assets/css/customizer-controls.css
Script Paths
/wp-content/plugins/pressfore-preloaders/assets/js/customizer-controls.js
Version Parameters
pressfore-preloaders/assets/js/customizer-controls.js?ver=pressfore-preloaders/assets/css/customizer-controls.css?ver=

HTML / DOM Fingerprints

CSS Classes
pf-gi-preloader-containerpf-gi-load-containercssload-flex-containercssload-loadingcssload-loading-centerhas-preloaderfountainTextGcssload-inner+6 more
Data Attributes
data-type
JS Globals
PF_Preloaders_Radio_Image
Shortcode Output
<div class="pf-gi-preloader-container"><div class="pf-gi-load-container"><ul class="cssload-flex-container"><li><span class="cssload-loading cssload-one"></span><span class="cssload-loading cssload-two"></span><span class="cssload-loading-center"></span></li></ul></div></div>
FAQ

Frequently Asked Questions about Pressfore Preloaders