
SyntaxHighlighter Plus Security & Risk Analysis
wordpress.org/plugins/syntaxhighlighter-plusEasily post source code such as PHP or HTML and display it in a styled box.
Is SyntaxHighlighter Plus Safe to Use in 2026?
Generally Safe
Score 85/100SyntaxHighlighter Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "syntaxhighlighter-plus" v1.0b2 plugin exhibits a generally good security posture based on the provided static analysis. The plugin has a notably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, all of which are positive security indicators. The presence of nonce and capability checks is also a strength. However, a significant concern arises from the fact that 100% of the identified output operations are not properly escaped. This lack of output escaping represents a substantial risk for Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data, if not sanitized before display, could be executed as JavaScript in the browser of other users or administrators. The vulnerability history is clean, with no known CVEs, which suggests a positive track record for this plugin, but this should not overshadow the critical flaw found in output handling.
Key Concerns
- Unescaped output detected
SyntaxHighlighter Plus Security Vulnerabilities
SyntaxHighlighter Plus Release Timeline
SyntaxHighlighter Plus Code Analysis
Output Escaping
SyntaxHighlighter Plus Attack Surface
WordPress Hooks 15
Maintenance & Trust
SyntaxHighlighter Plus Maintenance & Trust
Maintenance Signals
Community Trust
SyntaxHighlighter Plus Alternatives
SyntaxHighlighter Evolved
syntaxhighlighter
Easily post syntax-highlighted code to your site without having to modify the code at all. As seen on WordPress.com.
SyntaxHighlighter2
syntaxhighlighter2
Easily post source code such as PHP or HTML and display it in a styled box.
Code View
code-view
Easily use highlightjs and line-numbers to syntax-highlighted sample code on your blog posts
SyntaxHighlighter Evolved: ABAP Brush
syntaxhighlighter-evolved-abap-brush
This is a Advanced Business Application Programming (ABAP) brush for the "SyntaxHighlighter Evolved" plugin.
SyntaxHighlighter Amplified
syntaxhighlighter-amplified
Easily post syntax-highlighted code to your site without having to modify the code at all. Compatible with AMP pages.
SyntaxHighlighter Plus Developer Profile
1 plugin · 100 total installs
How We Detect SyntaxHighlighter Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/syntaxhighlighter-plus/syntaxhighlighter/styles/shCore.css/wp-content/plugins/syntaxhighlighter-plus/syntaxhighlighter/styles/shThemeDefault.css/wp-content/plugins/syntaxhighlighter-plus/syntaxhighlighter/scripts/shCore.js/wp-content/plugins/syntaxhighlighter-plus/syntaxhighlighter/scripts/shAutoloader.jssyntaxhighlighter-plus/syntaxhighlighter/styles/shCore.css?ver=syntaxhighlighter-plus/syntaxhighlighter/styles/syntaxhighlighter-plus/syntaxhighlighter/scripts/shCore.js?ver=syntaxhighlighter-plus/syntaxhighlighter/scripts/shAutoloader.js?ver=HTML / DOM Fingerprints
syntaxhighlightersyntaxhighlighter-overflowsyntaxhighlighter-wrapper START SyntaxHighlighter core END SyntaxHighlighter core START SyntaxHighlighter theme END SyntaxHighlighter theme+2 moredata-syntaxhighlightSyntaxHighlighter[sourcecode language="[/sourcecode][source language="[/source]