SyntaxHighlighter CKEditor Button Security & Risk Analysis

wordpress.org/plugins/syntaxhighlighter-ckeditor-button

This plugin adds a code button for WordPress CKEditor which helps to type or edit tag for Alex Gorbatchev's SyntaxHighlighter.

80 active installs v1.2.2 PHP + WP 3.3+ Updated Apr 21, 2014
ckeditorsyntaxhighlighter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SyntaxHighlighter CKEditor Button Safe to Use in 2026?

Generally Safe

Score 85/100

SyntaxHighlighter CKEditor Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The syntaxhighlighter-ckeditor-button plugin v1.2.2 exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the data indicates a commitment to secure database interactions, with all SQL queries utilizing prepared statements. The lack of dangerous functions, file operations, external HTTP requests, and reported vulnerabilities in its history are all positive indicators of good security practices.

However, a significant concern arises from the output escaping analysis. With one total output identified and 0% properly escaped, this indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. While the static analysis did not detect any taint flows, this could be due to the limited scope of the analysis or the nature of the code. The complete absence of nonce and capability checks across all potential entry points (even though there are none explicitly identified in the static analysis) also suggests a potential for broader issues if new entry points are introduced without proper security measures.

In conclusion, the plugin's small attack surface and secure database practices are commendable. The primary area of concern is the unescaped output, which presents a direct risk of XSS. The absence of any recorded vulnerabilities in the history is a strong positive signal, suggesting the developers have historically prioritized security. However, the lack of output escaping needs immediate attention to solidify its security profile.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

SyntaxHighlighter CKEditor Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SyntaxHighlighter CKEditor Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

SyntaxHighlighter CKEditor Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedsyntaxHighlighter-ckeditor-button.php:16
actionadmin_enqueue_scriptssyntaxHighlighter-ckeditor-button.php:17
actionadmin_print_footer_scriptssyntaxHighlighter-ckeditor-button.php:18
actioninitsyntaxHighlighter-ckeditor-button.php:20
filterckeditor_external_pluginssyntaxHighlighter-ckeditor-button.php:23
filterckeditor_buttonssyntaxHighlighter-ckeditor-button.php:24
Maintenance & Trust

SyntaxHighlighter CKEditor Button Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedApr 21, 2014
PHP min version
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

SyntaxHighlighter CKEditor Button Developer Profile

solagirl

1 plugin · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SyntaxHighlighter CKEditor Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/syntaxhighlighter-ckeditor-button/syntaxhighlight/

HTML / DOM Fingerprints

JS Globals
ckeditor_syntaxhighlighter_admin_noticeckeditor_syntaxhighlighterckeditor_syntaxhighlighter_button
FAQ

Frequently Asked Questions about SyntaxHighlighter CKEditor Button