
Vaaky Highlighter – Syntax Highlighter for Gutenberg Security & Risk Analysis
wordpress.org/plugins/vaaky-highlighterLightweight syntax highlighter plugin for WordPress Gutenberg powered by Highlight.js. Add beautiful, fast, and responsive code blocks with ease.
Is Vaaky Highlighter – Syntax Highlighter for Gutenberg Safe to Use in 2026?
Generally Safe
Score 100/100Vaaky Highlighter – Syntax Highlighter for Gutenberg has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The vaaky-highlighter plugin, version 1.1.0, exhibits a generally good security posture, particularly in its handling of SQL queries and its limited attack surface. The absence of known CVEs and the presence of capability checks are positive indicators. However, a significant concern arises from the taint analysis, which reveals one flow with unsanitized paths. While the static analysis did not classify this as critical or high severity, it's a crucial area that requires immediate attention as it could potentially lead to vulnerabilities if exploited.
Furthermore, the low percentage of properly escaped output (17%) is a notable weakness. This indicates that a substantial number of data outputs are not being properly sanitized, increasing the risk of cross-site scripting (XSS) vulnerabilities. The plugin also lacks nonce checks, which, while not explicitly tied to an attack vector in this analysis, is a standard WordPress security practice that should be implemented, especially for any dynamic functionality that might be introduced later. The vulnerability history shows no past issues, which is a strong positive, but the current code quality concerns, particularly regarding unsanitized paths and output escaping, cannot be overlooked.
Key Concerns
- Unsanitized paths identified in taint analysis
- Low percentage of properly escaped output
- No nonce checks on entry points
Vaaky Highlighter – Syntax Highlighter for Gutenberg Security Vulnerabilities
Vaaky Highlighter – Syntax Highlighter for Gutenberg Code Analysis
Output Escaping
Data Flow Analysis
Vaaky Highlighter – Syntax Highlighter for Gutenberg Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Vaaky Highlighter – Syntax Highlighter for Gutenberg Maintenance & Trust
Maintenance Signals
Community Trust
Vaaky Highlighter – Syntax Highlighter for Gutenberg Alternatives
CodeMirror Blocks
wp-codemirror-block
CodeMirror Blocks is useful for tutorial site where display formatted (highlighted) code block. With support of 100+ Language/Mode and 56 Themes.
Code Manager
code-manager
Write, test and deploy PHP, JavaScript, CSS and HTML code blocks from the WordPress dashboard.
Code Block – Embed Code with One-Click Copy Feature
code-snippets-block
Display beautifully highlighted code snippets on your WordPress site with a one-click copy feature. Fully responsive and Gutenberg compatible.
Snippets Block
snippets-block
Allows to add snippets blocks to your content: Javascript, CSS, HTML...
Blocksolid Snippets
blocksolid-snippets
Snippets functionality with a custom post type, shortcode and optional Gutenberg block.
Vaaky Highlighter – Syntax Highlighter for Gutenberg Developer Profile
1 plugin · 20 total installs
How We Detect Vaaky Highlighter – Syntax Highlighter for Gutenberg
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vaaky-highlighter/Admin/css/gutenberg.css/wp-content/plugins/vaaky-highlighter/Admin/js/gutenberg.js/wp-content/plugins/vaaky-highlighter/Frontend/css/frontend.css/wp-content/plugins/vaaky-highlighter/Frontend/js/frontend.js/wp-content/plugins/vaaky-highlighter/Admin/js/gutenberg.js/wp-content/plugins/vaaky-highlighter/Frontend/js/frontend.jsvaaky-highlighter/Admin/css/gutenberg.css?ver=vaaky-highlighter/Admin/js/gutenberg.js?ver=vaaky-highlighter/Frontend/css/frontend.css?ver=vaaky-highlighter/Frontend/js/frontend.js?ver=HTML / DOM Fingerprints
vaaky-highlighter-wrapdata-vaaky-highlightervaakyHighlighterFrontend