Vaaky Highlighter – Syntax Highlighter for Gutenberg Security & Risk Analysis

wordpress.org/plugins/vaaky-highlighter

Lightweight syntax highlighter plugin for WordPress Gutenberg powered by Highlight.js. Add beautiful, fast, and responsive code blocks with ease.

20 active installs v1.1.0 PHP 5.6+ WP 6.0+ Updated Jan 10, 2026
code-blocksgutenberghighlight-jssnippetssyntax-highlighter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Vaaky Highlighter – Syntax Highlighter for Gutenberg Safe to Use in 2026?

Generally Safe

Score 100/100

Vaaky Highlighter – Syntax Highlighter for Gutenberg has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The vaaky-highlighter plugin, version 1.1.0, exhibits a generally good security posture, particularly in its handling of SQL queries and its limited attack surface. The absence of known CVEs and the presence of capability checks are positive indicators. However, a significant concern arises from the taint analysis, which reveals one flow with unsanitized paths. While the static analysis did not classify this as critical or high severity, it's a crucial area that requires immediate attention as it could potentially lead to vulnerabilities if exploited.

Furthermore, the low percentage of properly escaped output (17%) is a notable weakness. This indicates that a substantial number of data outputs are not being properly sanitized, increasing the risk of cross-site scripting (XSS) vulnerabilities. The plugin also lacks nonce checks, which, while not explicitly tied to an attack vector in this analysis, is a standard WordPress security practice that should be implemented, especially for any dynamic functionality that might be introduced later. The vulnerability history shows no past issues, which is a strong positive, but the current code quality concerns, particularly regarding unsanitized paths and output escaping, cannot be overlooked.

Key Concerns

  • Unsanitized paths identified in taint analysis
  • Low percentage of properly escaped output
  • No nonce checks on entry points
Vulnerabilities
None known

Vaaky Highlighter – Syntax Highlighter for Gutenberg Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Vaaky Highlighter – Syntax Highlighter for Gutenberg Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
30
6 escaped
Nonce Checks
0
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped36 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<setting-sidebar> (Admin\partials\setting-sidebar.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Vaaky Highlighter – Syntax Highlighter for Gutenberg Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[vaakyHighlighterCode] Frontend\Frontend.php:90
WordPress Hooks 8
actionadmin_enqueue_scriptsAdmin\Admin.php:75
actionadmin_enqueue_scriptsAdmin\Admin.php:76
actionadmin_menuAdmin\Settings.php:134
actionadmin_initAdmin\Settings.php:135
actionwp_enqueue_scriptsFrontend\Frontend.php:87
actionwp_enqueue_scriptsFrontend\Frontend.php:88
actionplugins_loadedIncludes\I18n.php:50
actionwpmu_new_blogvaaky-highlighter.php:91
Maintenance & Trust

Vaaky Highlighter – Syntax Highlighter for Gutenberg Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 10, 2026
PHP min version5.6
Downloads4K

Community Trust

Rating90/100
Number of ratings2
Active installs20
Developer Profile

Vaaky Highlighter – Syntax Highlighter for Gutenberg Developer Profile

WebHat

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Vaaky Highlighter – Syntax Highlighter for Gutenberg

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vaaky-highlighter/Admin/css/gutenberg.css/wp-content/plugins/vaaky-highlighter/Admin/js/gutenberg.js/wp-content/plugins/vaaky-highlighter/Frontend/css/frontend.css/wp-content/plugins/vaaky-highlighter/Frontend/js/frontend.js
Script Paths
/wp-content/plugins/vaaky-highlighter/Admin/js/gutenberg.js/wp-content/plugins/vaaky-highlighter/Frontend/js/frontend.js
Version Parameters
vaaky-highlighter/Admin/css/gutenberg.css?ver=vaaky-highlighter/Admin/js/gutenberg.js?ver=vaaky-highlighter/Frontend/css/frontend.css?ver=vaaky-highlighter/Frontend/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
vaaky-highlighter-wrap
Data Attributes
data-vaaky-highlighter
JS Globals
vaakyHighlighterFrontend
FAQ

Frequently Asked Questions about Vaaky Highlighter – Syntax Highlighter for Gutenberg