
SCSS WP Editor Security & Risk Analysis
wordpress.org/plugins/scss-wp-editorEasily Add, Compile and Optimize your SCSS to CSS within WordPress Admin.
Is SCSS WP Editor Safe to Use in 2026?
Mostly Safe
Score 79/100SCSS WP Editor is generally safe to use. 1 past CVE were resolved. Keep it updated.
The SCSS WP Editor plugin v1.2.1 exhibits a mixed security posture. On one hand, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output. It also has a limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication checks. However, significant concerns arise from the presence of dangerous functions like `unserialize` and `assert`, and a notable lack of nonce checks and capability checks throughout the code. The taint analysis reveals flows with unsanitized paths, although currently classified as low severity. The plugin's vulnerability history is particularly worrying, with one unpatched medium-severity CVE related to Cross-Site Request Forgery (CSRF), and the fact that the last vulnerability was in the future (2025-04-01) suggests potential data inaccuracies or future known issues. While the plugin has strengths in data handling and output sanitization, the potential for arbitrary code execution via `unserialize` and the historical CSRF vulnerability, coupled with a general absence of authorization controls, necessitates caution.
Key Concerns
- Unpatched CVE
- Dangerous functions detected (unserialize, assert)
- Flows with unsanitized paths
- Zero nonce checks
- Zero capability checks
SCSS WP Editor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SCSS WP Editor <= 1.1.8 - Cross-Site Request Forgery
SCSS WP Editor Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
SCSS WP Editor Attack Surface
WordPress Hooks 10
Maintenance & Trust
SCSS WP Editor Maintenance & Trust
Maintenance Signals
Community Trust
SCSS WP Editor Alternatives
SiteOrigin CSS
so-css
Powerful, simple CSS editing for WordPress. Visual controls & real-time previews for effortless site customization.
WP-SCSS
wp-scss
Compiles .scss files to .css and enqueues them.
Visual CSS Style Editor
yellow-pencil-visual-theme-customizer
Style your WordPress site visually. Discover the most popular front-end design plugin! Try live demo.
WP-LESS
wp-less
Implementation of LESS (Leaner CSS) in order to make themes development easier.
Blocks CSS: CSS Editor for Gutenberg Blocks
blocks-css
Blocks CSS allows you add custom CSS to your Blocks straight from the Block Editor (Gutenberg).
SCSS WP Editor Developer Profile
10 plugins · 11K total installs
How We Detect SCSS WP Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scss-wp-editor/admin/css/scss-wp-editor-admin.css/wp-content/plugins/scss-wp-editor/admin/js/scss-wp-editor-admin.js/wp-content/plugins/scss-wp-editor/admin/js/scss-wp-editor-admin.jsscss-wp-editor/admin/css/scss-wp-editor-admin.css?ver=scss-wp-editor/admin/js/scss-wp-editor-admin.js?ver=HTML / DOM Fingerprints
data-codemirror-editorcm_settings