WP Simple and Nice Preloader Security & Risk Analysis

wordpress.org/plugins/wp-simple-and-nice-preloader

This plugin is developed to add nice preloaders on your wordpress site.

50 active installs v1.0.0 PHP + WP 3.0+ Updated Nov 1, 2014
nice-preloaderpage-loadpage-loaderpage-spinnerspreloader
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Simple and Nice Preloader Safe to Use in 2026?

Generally Safe

Score 85/100

WP Simple and Nice Preloader has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "wp-simple-and-nice-preloader" plugin v1.0.0 presents a mixed security posture. On the positive side, it demonstrates a strong absence of known vulnerabilities (CVEs) and a clean history, suggesting a generally well-maintained codebase. The static analysis also indicates no dangerous functions, SQL queries executed using prepared statements, file operations, external HTTP requests, or bundled libraries, which are all excellent security practices. Furthermore, the plugin boasts a very small attack surface with zero identified entry points that lack authentication checks.

However, significant concerns arise from the code analysis regarding output escaping. The fact that 100% of the 34 identified output points are not properly escaped is a critical security weakness. This suggests a high potential for Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the user's browser. The taint analysis also revealed two flows with unsanitized paths, which, while not classified as critical or high severity in this specific scan, further points to potential injection vulnerabilities that were not fully mitigated. The absence of nonce and capability checks also means that even if an entry point existed, it would be unprotected against CSRF attacks or unauthorized actions.

In conclusion, while the plugin has a pristine vulnerability history and a small attack surface, the lack of output escaping is a severe oversight that significantly increases the risk profile. The presence of unsanitized paths in the taint analysis, though not severe in this instance, reinforces the need for more robust input validation and output sanitization. Developers should prioritize addressing the output escaping issues to mitigate XSS risks.

Key Concerns

  • 100% of outputs are not properly escaped
  • Taint flows with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

WP Simple and Nice Preloader Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Simple and Nice Preloader Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped34 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
wpsnp_admin_function (wpsnp_preloader.php:35)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Simple and Nice Preloader Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuwpsnp_preloader.php:20
actionwp_enqueue_scriptswpsnp_preloader.php:205
Maintenance & Trust

WP Simple and Nice Preloader Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedNov 1, 2014
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings4
Active installs50
Developer Profile

WP Simple and Nice Preloader Developer Profile

ShawonPro

1 plugin · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Simple and Nice Preloader

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-simple-and-nice-preloader/icon/atom.jpg/wp-content/plugins/wp-simple-and-nice-preloader/icon/barbar.jpg/wp-content/plugins/wp-simple-and-nice-preloader/icon/big-counter.jpg/wp-content/plugins/wp-simple-and-nice-preloader/icon/bounce.jpg/wp-content/plugins/wp-simple-and-nice-preloader/icon/circle_count.jpg/wp-content/plugins/wp-simple-and-nice-preloader/icon/fill-left.jpg/wp-content/plugins/wp-simple-and-nice-preloader/icon/flash.jpg/wp-content/plugins/wp-simple-and-nice-preloader/icon/flat-top.jpg+13 more

HTML / DOM Fingerprints

CSS Classes
wpsnp
FAQ

Frequently Asked Questions about WP Simple and Nice Preloader