
Snillrik Settings Security & Risk Analysis
wordpress.org/plugins/snillrik-settingsTo easily turn on and off some settings that often is done with hooks, hacks or filters in WordPress.
Is Snillrik Settings Safe to Use in 2026?
Generally Safe
Score 100/100Snillrik Settings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "snillrik-settings" v1.5.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and showing a high percentage of properly escaped output. The absence of file operations, external HTTP requests, and bundled libraries further reduces potential attack vectors. Furthermore, the vulnerability history is clean, with no recorded CVEs, suggesting a historically stable codebase.
However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks. This represents a substantial attack surface that could be exploited by unauthenticated users to trigger unintended actions or access sensitive data. The lack of capability checks on these entry points exacerbates this risk, as any user, regardless of their role or permissions, could potentially interact with these handlers.
In conclusion, while the plugin uses secure coding practices for database interactions and output handling, the unprotected AJAX endpoints are a critical vulnerability. The absence of any recorded vulnerabilities in its history is a positive sign, but it does not negate the immediate risks posed by the exposed AJAX functionality. Mitigation efforts should prioritize securing these entry points.
Key Concerns
- AJAX handlers without authentication checks
- AJAX handlers without capability checks
- Some output not properly escaped
Snillrik Settings Security Vulnerabilities
Snillrik Settings Code Analysis
SQL Query Safety
Output Escaping
Snillrik Settings Attack Surface
AJAX Handlers 2
WordPress Hooks 58
Maintenance & Trust
Snillrik Settings Maintenance & Trust
Maintenance Signals
Community Trust
Snillrik Settings Alternatives
No alternatives data available yet.
Snillrik Settings Developer Profile
3 plugins · 30 total installs
How We Detect Snillrik Settings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/snillrik-settings/css/settings-page.css/wp-content/plugins/snillrik-settings/css/snillrik-settings.css/wp-content/plugins/snillrik-settings/js/jscolor.min.js/wp-content/plugins/snillrik-settings/js/snillrik-settings.js/wp-content/plugins/snillrik-settings/js/jscolor.min.js/wp-content/plugins/snillrik-settings/js/snillrik-settings.jssnillrik-settings/css/settings-page.css?ver=snillrik-settings/css/snillrik-settings.css?ver=snillrik-settings/js/jscolor.min.js?ver=snillrik-settings/js/snillrik-settings.js?ver=HTML / DOM Fingerprints
snillrik-settings-sliderid="snillrik_settings_turnoffemoji"name="snillrik_settings_turnoffemoji"id="snillrik_settings_categorycolor"name="snillrik_settings_categorycolor"SNILLRIK_SETTINGS_PLUGIN_URLSNILLRIK_SETTINGS_NAMESNILLRIK_SETTINGS_SWITCHNAME