Thirteen Colors Security & Risk Analysis

wordpress.org/plugins/thirteen-colors

Thirteen Colors is the easiest way to customize the colors of the Twenty Thirteen theme.

200 active installs v1.0 PHP + WP 3.6+ Updated Jul 10, 2016
colorscustomcustom-colorstheme-customizertwenty-thirteen
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Thirteen Colors Safe to Use in 2026?

Generally Safe

Score 85/100

Thirteen Colors has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'thirteen-colors' v1.0 plugin exhibits a generally good security posture regarding its attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. The absence of known CVEs and recorded vulnerabilities further suggests a history of secure development or minimal exposure. However, the static analysis reveals significant concerns in output escaping, with 100% of identified outputs being unescaped. This is a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities if any dynamic data is rendered to the user interface without proper sanitization. Additionally, the presence of file operations without clear context or safeguards warrants attention. While the plugin avoids dangerous functions and uses prepared statements for its SQL queries, the unescaped output presents a substantial risk that needs immediate remediation.

Key Concerns

  • 100% of outputs are unescaped
  • File operations present without context
Vulnerabilities
None known

Thirteen Colors Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Thirteen Colors Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped20 total outputs
Attack Surface

Thirteen Colors Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioncustomize_registerthirteen-colors.php:36
actioncustomize_render_control_header_imagethirteen-colors.php:39
actionwp_headthirteen-colors.php:42
actioncustomize_save_afterthirteen-colors.php:45
filtermce_cssthirteen-colors.php:48
Maintenance & Trust

Thirteen Colors Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedJul 10, 2016
PHP min version
Downloads9K

Community Trust

Rating94/100
Number of ratings3
Active installs200
Developer Profile

Thirteen Colors Developer Profile

Nick Halsey

27 plugins · 24K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Thirteen Colors

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/thirteen-colors/thirteen-colors.php

HTML / DOM Fingerprints

CSS Classes
thirteen-colors-header-link
FAQ

Frequently Asked Questions about Thirteen Colors