
WP Custom Code Security & Risk Analysis
wordpress.org/plugins/wp-custom-codeAdd CSS and Javascript to your pages simply and quickly. WP Custom Code supports CodeMirror.
Is WP Custom Code Safe to Use in 2026?
Generally Safe
Score 85/100WP Custom Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-custom-code" plugin v1.1.0 exhibits a generally positive security posture based on the provided static analysis. The absence of identified dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests is a strong indicator of secure coding practices. The use of prepared statements for all SQL queries and the presence of a nonce check further bolster its security. The plugin also boasts a clean vulnerability history with no recorded CVEs, suggesting a track record of security diligence.
However, there are areas for improvement. The most significant concern is the low percentage (44%) of properly escaped outputs. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. While the attack surface is currently zero, this is not a static metric and future development could introduce new entry points. The lack of capability checks on the single nonce check, while not necessarily a vulnerability in itself, could be strengthened to ensure the nonce is checked in conjunction with user permissions for more robust protection.
In conclusion, "wp-custom-code" v1.1.0 is a relatively secure plugin due to its clean history and avoidance of common vulnerabilities. The primary area of concern is output escaping, which should be addressed to mitigate potential XSS risks. The absence of critical issues in the static analysis and vulnerability history is a strong positive, but ongoing vigilance and attention to output sanitation are recommended.
Key Concerns
- Insufficient output escaping
WP Custom Code Security Vulnerabilities
WP Custom Code Code Analysis
Output Escaping
WP Custom Code Attack Surface
WordPress Hooks 11
Maintenance & Trust
WP Custom Code Maintenance & Trust
Maintenance Signals
Community Trust
WP Custom Code Alternatives
Scripts n Styles
scripts-n-styles
This plugin allows Admin users to individually add HTML, custom CSS, Classes and JavaScript directly to Post, Pages or any other custom post types.
Code Embed
simple-embed-code
Code Embed provides a very easy and efficient way to embed code (JavaScript, CSS and HTML) in your posts and pages.
Add Code To Head
add-code-to-head
Add custom Javascript/HTML/CSS codes to the page head without editing the template.
WebberZone Snippetz – Header, Body and Footer manager
add-to-all
The ultimate snippet manager for WordPress. Create and manage custom HTML, CSS, or JS code snippets and control where and when they are displayed.
Code Manager
code-manager
Write, test and deploy PHP, JavaScript, CSS and HTML code blocks from the WordPress dashboard.
WP Custom Code Developer Profile
2 plugins · 20 total installs
How We Detect WP Custom Code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-custom-code/css/style.css/wp-content/plugins/wp-custom-code/js/script.js/wp-content/plugins/wp-custom-code/js/script.jswp-custom-code/css/style.css?ver=wp-custom-code/js/script.js?ver=HTML / DOM Fingerprints
<!-- WP Custom Code -->data-nonce="kfag_custom_code_admin_metabox_nonce"cm_settings