
WP Nice Loader Security & Risk Analysis
wordpress.org/plugins/wp-nice-loaderWP Nice Loader allows you control over page preloader, font size, themes and more.
Is WP Nice Loader Safe to Use in 2026?
Mostly Safe
Score 71/100WP Nice Loader is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "wp-nice-loader" plugin v0.1.0.4 presents a mixed security posture. While the static analysis reveals a commendable lack of direct attack surface (no AJAX handlers, REST API routes, shortcodes, or cron events), indicating a potentially secure by obscurity approach, there are significant concerns. A considerable portion (67%) of output is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if any of the output is user-controlled. Furthermore, the plugin has a known medium severity vulnerability (CSRF) that remains unpatched, and this is the second known vulnerability of this type, suggesting a recurring pattern of security oversight.
The taint analysis did not uncover any issues, and the code uses prepared statements for SQL queries, which are positive security indicators. However, the lack of nonce checks and the fact that only one capability check is present for the entire plugin raises questions about the robustness of its internal access controls. The history of CSRF vulnerabilities, especially with a medium severity rating, is a notable red flag that cannot be ignored, even if the current static analysis doesn't highlight it directly. This indicates a potential blind spot in the development process for handling sensitive operations.
In conclusion, while "wp-nice-loader" exhibits some good practices like avoiding a large attack surface and using prepared statements, the unpatched CSRF vulnerability, combined with a high rate of unescaped output, points to significant risks. The developer should prioritize addressing the known vulnerability and improving output sanitization to enhance the plugin's overall security.
Key Concerns
- Unpatched medium severity CVE
- High percentage of unescaped output
- Lack of nonce checks
- Limited capability checks
WP Nice Loader Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Nice Loader <= 0.1.0.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting
WP Nice Loader Code Analysis
Output Escaping
Data Flow Analysis
WP Nice Loader Attack Surface
WordPress Hooks 7
Maintenance & Trust
WP Nice Loader Maintenance & Trust
Maintenance Signals
Community Trust
WP Nice Loader Alternatives
LoftLoader
loftloader
An easy to use plugin to add an animated preloader to your website with fully customisations.
Safelayout Cute Preloader – CSS3 WordPress Preloader
safelayout-cute-preloader
Easily add a pure CSS animated preloader to your WordPress website.
Preloader
the-preloader
The ultimate Preloader plugin for WordPress. Smart, flexible, and made for easy control. Add a preloader to your website easily in only 3 steps.
WP Smart Preloader
wp-smart-preloader
A Plugin to add awesome collection of Loaders and Spinners. Delightful and performance-focused Pure CSS animations.
Flat Preloader
flat-preloader
Flat Preloader helps you create the loading page with many excited gif icons.
WP Nice Loader Developer Profile
2 plugins · 10K total installs
How We Detect WP Nice Loader
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-nice-loader/assets/admin-style.css/wp-content/plugins/wp-nice-loader/assets/plugins/jqColorPicker.min.js/wp-content/plugins/wp-nice-loader/assets/admin-scripts.js/wp-content/plugins/wp-nice-loader/assets/front-styles.css/wp-content/plugins/wp-nice-loader/assets/front-scripts.js/wp-content/plugins/wp-nice-loader/assets/plugins/jqColorPicker.min.js/wp-content/plugins/wp-nice-loader/assets/admin-scripts.js/wp-content/plugins/wp-nice-loader/assets/front-scripts.jsHTML / DOM Fingerprints
wp_nice_loader_body