
WP Fossil Security & Risk Analysis
wordpress.org/plugins/wp-fossilProvides support for media queries and emulating CSS3 pseudo-classes and attribute selectors in Internet Explorer 6-8.
Is WP Fossil Safe to Use in 2026?
Generally Safe
Score 85/100WP Fossil has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-fossil" plugin v1.0 exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of detected AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code analysis shows no dangerous functions, no file operations, no external HTTP requests, and no taint analysis findings, all of which are positive indicators. The SQL queries are all prepared, which is a good practice.
However, a significant concern arises from the output escaping. With 100% of outputs not properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed by the plugin without proper sanitization could be exploited. Additionally, the complete lack of nonce checks and capability checks, combined with zero detected entry points, is an anomaly. While a zero attack surface is good, the absence of these fundamental security checks suggests that either the plugin is exceptionally simple and has no dynamic content, or there's a possibility that the analysis tools did not correctly identify all entry points or the need for these checks. The clean vulnerability history is positive but doesn't negate the identified code-level risks.
In conclusion, while "wp-fossil" v1.0 benefits from a minimal attack surface and good SQL practices, the unescaped outputs create a critical weakness that could lead to XSS. The absence of nonce and capability checks warrants further investigation to ensure the plugin is not inadvertently exposing functionality. The plugin's security is compromised by its handling of output data, despite other positive indicators.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
WP Fossil Security Vulnerabilities
WP Fossil Code Analysis
Output Escaping
WP Fossil Attack Surface
WordPress Hooks 1
Maintenance & Trust
WP Fossil Maintenance & Trust
Maintenance Signals
Community Trust
WP Fossil Alternatives
Compatiblizr
compatiblizr
Plugin for patching old versions of IE (7 and 8)to work with CSS3 selectors and Media Queries.
Standout CSS3 Buttons
standout-css3-buttons
Display CSS3 style buttons with gradient color styles on your website using shortcodes or PHP function call.
Bootstrap img-responsive
img-responsive
Automatically add img-responsive class to all post and page content.
Bootstrap v4 img-fluid
img-fluid
Automatically add img-fluid class to all post and page content.
Ultimate CSS Gradient Maker
ultimate-css-gradient-maker
Wrap any page or post content in a completely customizable CSS background gradient, quickly and easily
WP Fossil Developer Profile
3 plugins · 1K total installs
How We Detect WP Fossil
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-fossil/assets/js/build/ie.min.js/wp-content/plugins/wp-fossil/assets/js/build/ie.min.jsHTML / DOM Fingerprints
<![if lt IE 9]>