Simple Colorbox Security & Risk Analysis

wordpress.org/plugins/simple-colorbox

Description: Adds a very simple Colorbox to your linked images.

1K active installs v1.6.1 PHP + WP 3.9+ Updated Nov 28, 2017
colorboxhoverlayoverlightboxsimple
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 26, 2025
Safety Verdict

Is Simple Colorbox Safe to Use in 2026?

Use With Caution

Score 63/100

Simple Colorbox has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 26, 2025Updated 8yr ago
Risk Assessment

The static analysis of simple-colorbox v1.6.1 reveals a strong adherence to secure coding practices. The absence of dangerous functions, SQL injection vulnerabilities, file operations, external HTTP requests, and the proper use of prepared statements and output escaping for all identified code paths are commendable. Furthermore, the plugin has a minimal attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that appear to be unprotected. This indicates a generally robust security posture within the current codebase.

However, the presence of a known, unpatched medium-severity vulnerability (CVE) is a significant concern. While the static analysis might not have detected this specific issue, its existence means users of this plugin are exposed to a known risk. The historical vulnerability pattern, with a medium-severity XSS issue being the most recent, suggests a potential for input sanitization or output encoding weaknesses that may not have been fully addressed or were introduced in subsequent changes not reflected in this static analysis. This unpatched vulnerability should be the primary focus for mitigation.

In conclusion, while the codebase itself appears to be well-secured with good practices, the single unpatched medium-severity vulnerability drastically lowers the overall security rating. The plugin's strengths lie in its clean code and limited attack surface, but its weakness is the immediate risk posed by the known and unpatched CVE. Users must prioritize addressing this vulnerability.

Key Concerns

  • Unpatched medium-severity CVE
Vulnerabilities
1 published

Simple Colorbox Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-60124medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Colorbox <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 26, 2025Unpatched
Version History

Simple Colorbox Release Timeline

v1.6.1Current1 CVE
v1.61 CVE
v1.3.11 CVE
v1.31 CVE
v1.2.41 CVE
v1.2.21 CVE
v1.2.11 CVE
v1.21 CVE
v1.11 CVE
v1.0.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Simple Colorbox Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Simple Colorbox Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitindex.php:57
actionwp_enqueue_scriptsindex.php:58
actionwp_enqueue_scriptsindex.php:59
actionwp_headindex.php:60
actionplugins_loadedindex.php:172
Maintenance & Trust

Simple Colorbox Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedNov 28, 2017
PHP min version
Downloads41K

Community Trust

Rating96/100
Number of ratings12
Active installs1K
Developer Profile

Simple Colorbox Developer Profile

Ryan Hellyer

16 plugins · 97K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Colorbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-colorbox/themes/theme1/colorbox.css/wp-content/plugins/simple-colorbox/themes/theme2/colorbox.css/wp-content/plugins/simple-colorbox/themes/theme3/colorbox.css/wp-content/plugins/simple-colorbox/themes/theme4/colorbox.css/wp-content/plugins/simple-colorbox/themes/theme5/colorbox.css/wp-content/plugins/simple-colorbox/themes/theme6/colorbox.css/wp-content/plugins/simple-colorbox/themes/theme7/colorbox.css/wp-content/plugins/simple-colorbox/themes/theme8/colorbox.css+3 more
Script Paths
scripts/jquery.colorbox-min.js

HTML / DOM Fingerprints

HTML Comments
<!-- Simple Colorbox Plugin v1.6.1 by Ryan Hellyer ... https://geek.hellyer.kiwi/products/simple-colorbox/ -->
JS Globals
colorboxSettings
FAQ

Frequently Asked Questions about Simple Colorbox