
WP Page Loading Security & Risk Analysis
wordpress.org/plugins/wp-page-loading10+ layouts - Simple, light and great! Add preloader to your website easily, responsive and retina, full customization, compatible with all major brow …
Is WP Page Loading Safe to Use in 2026?
Generally Safe
Score 99/100WP Page Loading has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-page-loading" v1.0.7 plugin presents a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and appears to perform file operations and external HTTP requests cautiously, with no external requests detected. The presence of nonce and capability checks, while limited, is also a good sign. However, a significant concern lies in its attack surface, with two AJAX handlers, both lacking authentication checks. This creates direct entry points for potential unauthorized actions. Furthermore, while the static analysis did not identify dangerous functions or critical taint flows, the output escaping is only 63% properly implemented, leaving a portion of its output vulnerable to XSS attacks.
The plugin's vulnerability history, though currently showing no unpatched CVEs, is marked by a past medium-severity vulnerability (CSRF) discovered recently. This history, combined with the current lack of robust authentication on its AJAX endpoints, suggests a pattern of potential oversight in secure development practices. The plugin's strengths in SQL and file handling are overshadowed by its exposed AJAX endpoints and incomplete output sanitization, indicating a moderate risk profile that requires attention, particularly regarding the unprotected AJAX handlers.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
- Past medium vulnerability
WP Page Loading Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Page Loading <= 1.0.6 - Cross-Site Request Forgery
WP Page Loading Code Analysis
Output Escaping
WP Page Loading Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
WP Page Loading Maintenance & Trust
Maintenance Signals
Community Trust
WP Page Loading Alternatives
Stylish Preloader
stylish-preloader
Stylish Preloader plugin use for loading your wrodpress page. Stylish Preloader is integrated in the WordPress Customizer, so you can change every set …
Safelayout Cute Preloader – CSS3 WordPress Preloader
safelayout-cute-preloader
Easily add a pure CSS animated preloader to your WordPress website.
Preloader
the-preloader
The ultimate Preloader plugin for WordPress. Smart, flexible, and made for easy control. Add a preloader to your website easily in only 3 steps.
Flat Preloader
flat-preloader
Flat Preloader helps you create the loading page with many excited gif icons.
Preloader Awesome – Page Loading Animation with Spinner & Gif
preloader-awesome
Preloader Awesome help You to create page loading animation WordPress with spinner or You can upload Your own GIF.
WP Page Loading Developer Profile
1 plugin · 800 total installs
How We Detect WP Page Loading
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-page-loading/admin/js/main.js/wp-content/plugins/wp-page-loading/includes/layouts//wp-content/plugins/wp-page-loading/languages//wp-content/plugins/wp-page-loading/admin/js/main.jswp-page-loading/admin/js/main.js?ver=HTML / DOM Fingerprints
WP_PL_OBJ