WAJ Scripts Security & Risk Analysis

wordpress.org/plugins/waj-scripts

WordPress plugin for easily adding CSS stylesheets & JavaScript files.

0 active installs v1.1.1 PHP 7.0+ WP 5.0.0+ Updated Unknown
scripts
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WAJ Scripts Safe to Use in 2026?

Generally Safe

Score 100/100

WAJ Scripts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of the "waj-scripts" v1.1.1 plugin reveals an exceptionally clean codebase with no identified attack surface. There are no AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no obvious entry points into the plugin's functionality. Furthermore, the code adheres to secure coding practices by not utilizing dangerous functions, all SQL queries are prepared statements, and all outputs are properly escaped. There are also no file operations or external HTTP requests, and crucially, no nonce or capability checks are required because there are no user-interactive functionalities exposed. The vulnerability history is also completely clear, with zero known CVEs and no past vulnerabilities recorded. This indicates a strong security posture with excellent adherence to best practices. The lack of any identified risks in the static analysis and the absence of any past vulnerabilities suggest this plugin is currently very secure. The plugin's strengths lie in its minimal attack surface and robust adherence to secure coding principles. A weakness, albeit a minor one in this context, is the complete absence of capability checks and nonce checks, but this is directly attributable to the lack of exposed functionality, making it a non-issue in this specific case.

Vulnerabilities
None known

WAJ Scripts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WAJ Scripts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WAJ Scripts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptssrc\WPScripts.php:41
actionwp_enqueue_scriptssrc\WPScripts.php:71
Maintenance & Trust

WAJ Scripts Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WAJ Scripts Developer Profile

waughjai

4 plugins · 10 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WAJ Scripts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/waj-scripts/js//wp-content/plugins/waj-scripts/css/
Script Paths
waj-scripts/style.csswaj-scripts/script.js
Version Parameters
waj-scripts/style.css?ver=waj-scripts/script.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-meta-box-slug="page-js"data-meta-box-slug="page-css"
JS Globals
window.WaughJ
FAQ

Frequently Asked Questions about WAJ Scripts