
Syntax Highlighter Compress Security & Risk Analysis
wordpress.org/plugins/syntax-highlighter-compressSyntax Highlighter ComPress is a plugin for code syntax highlighting. It loads fast on the website and code can pasted easily into Wordpress.
Is Syntax Highlighter Compress Safe to Use in 2026?
Use With Caution
Score 63/100Syntax Highlighter Compress has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "syntax-highlighter-compress" plugin, version 3.0.83.3, exhibits a mixed security posture. While it boasts zero direct attack surface entry points (AJAX, REST API, shortcodes, cron events) that are unprotected, and all SQL queries appear to use prepared statements, several critical code signals raise significant concerns. The presence of the `create_function` function is a red flag, as it can be a source of code injection vulnerabilities if not handled with extreme care. Furthermore, the fact that 100% of its output is not properly escaped is a severe security flaw, paving the way for Cross-Site Scripting (XSS) attacks. The taint analysis also indicates a flow with unsanitized paths, which, despite not being classified as critical or high severity, still represents a potential risk of data manipulation or leakage.
The plugin's vulnerability history is particularly alarming. It has a known CVE with a medium severity, and critically, this vulnerability remains unpatched. The common vulnerability type being XSS reinforces the concerns identified in the static analysis regarding improper output escaping. The fact that the last vulnerability was recorded in the future (2026-01-16) is an anomaly that might indicate a data entry error, but it doesn't negate the presence of an existing, unpatched medium vulnerability. The plugin has a documented history of XSS, and its current code indicates a persistent weakness in output sanitization, making it susceptible to similar attacks.
In conclusion, while the plugin does not present a large direct attack surface and employs prepared statements for database operations, the substantial lack of output escaping, the use of `create_function`, and the existing unpatched XSS vulnerability paint a concerning picture. The potential for XSS attacks is high due to the unescaped output, and the unpatched CVE signifies an immediate risk to users. The plugin has demonstrable weaknesses in input sanitization and output encoding that have led to past vulnerabilities and continue to be a significant concern in its current state.
Key Concerns
- Unpatched Medium CVE
- 100% of outputs not properly escaped
- Taint flow with unsanitized paths
- Dangerous function: create_function
Syntax Highlighter Compress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Syntax Highlighter Compress <= 3.0.83.3 - Reflected Cross-Site Scripting
Syntax Highlighter Compress Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Syntax Highlighter Compress Attack Surface
WordPress Hooks 10
Maintenance & Trust
Syntax Highlighter Compress Maintenance & Trust
Maintenance Signals
Community Trust
Syntax Highlighter Compress Alternatives
WP SyntaxHighlighter
wp-syntaxhighlighter
This plugin is code syntax highlighter based on SyntaxHighlighter ver. 3.0.83 and 2.1.382.
Auto SyntaxHighlighter
auto-syntaxhighlighter
Auto SyntaxHighlighter is a WordPress Code highlight plugin. Use editor botton, in the pop-up window, paste or write your code, oh, very simple.
SyntaxHighlighter TinyMCE Button
syntaxhighlighter-tinymce-button
"SyntaxHighlighter TinyMCE Button" provides buttons for Visual Editor and will help to type <pre> tag for SyntaxHighlighter.
CodeMirror for CodeEditor
codemirror-for-codeeditor
Just another code syntaxhighligher for the theme and plugin editor with CodeMirror.
google-syntax
google-syntax
This is a code prettify plugin. the code higlighting effect will be seen directly in the mce editor.
Syntax Highlighter Compress Developer Profile
1 plugin · 100 total installs
How We Detect Syntax Highlighter Compress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/syntax-highlighter-compress/scripts/shCore.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushXml.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushSql.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushPlain.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushPerl.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushPhp.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushPython.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushRuby.js+15 more/wp-content/plugins/syntax-highlighter-compress/scripts/shCore.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushXml.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushSql.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushPlain.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushPerl.js/wp-content/plugins/syntax-highlighter-compress/scripts/shBrushPhp.js+9 moresyntax-highlighter-compress/scripts/shCore.js?ver=syntax-highlighter-compress/styles/shCore.css?ver=HTML / DOM Fingerprints
syntaxhighlighter-compresssh_mainSyntaxHighlighter