
Rocket Fireworks Security & Risk Analysis
wordpress.org/plugins/rocket-fireworksRocket Fireworks Celebration Plugin for your blog or website.
Is Rocket Fireworks Safe to Use in 2026?
Generally Safe
Score 85/100Rocket Fireworks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The rocket-fireworks plugin v1.4 exhibits a generally good security posture based on the provided static analysis. The absence of any identified dangerous functions, direct SQL queries (all are prepared), file operations, or external HTTP requests is a strong indicator of careful development. Furthermore, the lack of any recorded vulnerabilities, CVEs, or specific vulnerability types in its history suggests a history of security-conscious maintenance or a lack of targeting by attackers. The plugin also has a minimal attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. This limits potential entry points for malicious actors. However, a significant concern arises from the output escaping. With 100% of its outputs being unescaped, the plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. This represents a critical weakness that could be exploited to inject malicious scripts into the user's browser, leading to session hijacking, data theft, or defacement. While the plugin avoids common pitfalls, this widespread lack of output sanitization is a serious oversight that needs immediate attention.
Key Concerns
- All outputs unescaped
Rocket Fireworks Security Vulnerabilities
Rocket Fireworks Code Analysis
Output Escaping
Rocket Fireworks Attack Surface
WordPress Hooks 2
Maintenance & Trust
Rocket Fireworks Maintenance & Trust
Maintenance Signals
Community Trust
Rocket Fireworks Alternatives
Xmas Decoration
xmas-decoration
Decoration for your website at Christmas.
Happy New Year
happy-new-year
This plugin will create a good skin in your wordpress blog.
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
Rocket Fireworks Developer Profile
2 plugins · 170 total installs
How We Detect Rocket Fireworks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rocket-fireworks/js/rocket-fireworks.js/wp-content/plugins/rocket-fireworks/js/rocket-fireworks.jsHTML / DOM Fingerprints
RocketFireworksAnimationsdrfvars