Syntax-highlighting Code Block (with Server-side Rendering) Security & Risk Analysis

wordpress.org/plugins/syntax-highlighting-code-block

Extending the Code block with syntax highlighting rendered on the server, thus being AMP-compatible and having faster frontend performance.

1K active installs v1.5.1 PHP 7.4+ WP 6.6+ Updated Nov 30, 2025
blockcodecode-highlightingcode-syntaxsyntax-highlight
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Syntax-highlighting Code Block (with Server-side Rendering) Safe to Use in 2026?

Generally Safe

Score 100/100

Syntax-highlighting Code Block (with Server-side Rendering) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis for "syntax-highlighting-code-block" v1.5.1 reveals a very strong security posture. The plugin demonstrates excellent security practices with zero identified attack surface entry points, including AJAX handlers, REST API routes, shortcodes, and cron events. Crucially, there are no unprotected entry points. The code signals further reinforce this, showing no dangerous functions, 100% use of prepared statements for SQL queries, and 100% proper output escaping. File operations and external HTTP requests are also absent, minimizing potential risks.

The taint analysis found no flows with unsanitized paths, and there are no recorded vulnerabilities (CVEs) associated with this plugin. The complete absence of dangerous code signals and the thoroughness of its sanitization and escaping mechanisms indicate a well-developed and secure plugin. The presence of a capability check, even with no other entry points, is a good practice.

Overall, "syntax-highlighting-code-block" v1.5.1 appears to be a highly secure plugin. The lack of any identified vulnerabilities or exploitable code paths, coupled with robust coding practices, makes it a low-risk option. The only point to note is the absence of nonce checks, which is not a concern given the zero attack surface, but would become a critical omission if any entry points were ever added.

Vulnerabilities
None known

Syntax-highlighting Code Block (with Server-side Rendering) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Syntax-highlighting Code Block (with Server-side Rendering) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

Syntax-highlighting Code Block (with Server-side Rendering) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitinc\functions.php:33
actioncustomize_registerinc\functions.php:34
actionrest_api_initinc\functions.php:35
actionenqueue_block_assetsinc\functions.php:36
actionadmin_noticesinc\functions.php:185
actioncustomize_controls_enqueue_scriptsinc\functions.php:828
actionplugins_loadedsyntax-highlighting-code-block.php:73
Maintenance & Trust

Syntax-highlighting Code Block (with Server-side Rendering) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 30, 2025
PHP min version7.4
Downloads40K

Community Trust

Rating100/100
Number of ratings26
Active installs1K
Developer Profile

Syntax-highlighting Code Block (with Server-side Rendering) Developer Profile

Weston Ruter

22 plugins · 437K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
4499 days
View full developer profile
Detection Fingerprints

How We Detect Syntax-highlighting Code Block (with Server-side Rendering)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/syntax-highlighting-code-block/build/index.js/wp-content/plugins/syntax-highlighting-code-block/build/index.css
Script Paths
/wp-content/plugins/syntax-highlighting-code-block/build/index.js
Version Parameters
syntax-highlighting-code-block/build/index.js?ver=syntax-highlighting-code-block/build/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-codesyntax-highlighting-code-block
Data Attributes
data-languagedata-highlighted-linesdata-show-line-numbersdata-wrap-lines
JS Globals
syntaxHighlightingCodeBlock
REST Endpoints
/wp-json/syntax-highlighting-code-block/v1/themes
FAQ

Frequently Asked Questions about Syntax-highlighting Code Block (with Server-side Rendering)