Snippet Highlight Security & Risk Analysis

wordpress.org/plugins/snippet-highlight

Highlights your code snippets. With line numbering.

10 active installs v1.1 PHP + WP 2.1+ Updated Oct 28, 2007
codeformattinghighlightingpostsnippet
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Snippet Highlight Safe to Use in 2026?

Generally Safe

Score 85/100

Snippet Highlight has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 18yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'snippet-highlight' plugin version 1.1 exhibits an exceptionally strong security posture. The absence of any identified attack vectors like AJAX handlers, REST API routes, shortcodes, or cron events, combined with a complete lack of dangerous functions, file operations, and external HTTP requests, indicates a very small and well-contained codebase. Furthermore, the fact that all SQL queries utilize prepared statements and all outputs are properly escaped demonstrates adherence to fundamental WordPress security best practices, minimizing the risk of common vulnerabilities such as SQL injection and Cross-Site Scripting (XSS). The plugin's history of zero known CVEs further reinforces this assessment, suggesting a history of secure development and maintenance. There are no specific risks identified within the code analysis or taint flows presented. The primary strength is the apparent lack of exploitable entry points and secure coding practices. The only potential area for improvement, though not a direct risk based on this data, is the complete absence of nonces and capability checks, which might be considered for future hardening depending on the plugin's functionality, even though none are currently apparent. Overall, this plugin appears to be highly secure.

Vulnerabilities
None known

Snippet Highlight Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Snippet Highlight Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Snippet Highlight Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterwp_headsnippet-highlight.php:10
Maintenance & Trust

Snippet Highlight Maintenance & Trust

Maintenance Signals

WordPress version tested2.3.1
Last updatedOct 28, 2007
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Snippet Highlight Developer Profile

Roland Rust

9 plugins · 180 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Snippet Highlight

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/snippet-highlight/star-light/star-light.css/wp-content/plugins/snippet-highlight/linenumbers.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Snippet Highlight