
WP Skyscraper Security & Risk Analysis
wordpress.org/plugins/wp-skyscraperWP Skyscraper is a wordpress plugin that allows you to add fixed box on your wordpress blog.
Is WP Skyscraper Safe to Use in 2026?
Generally Safe
Score 85/100WP Skyscraper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-skyscraper v0.1 plugin exhibits a mixed security posture. On the positive side, the plugin does not appear to have any direct entry points through AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, it uses prepared statements exclusively for its SQL queries and has no recorded vulnerability history, suggesting a potentially careful development approach regarding common attack vectors and past security issues.
However, significant concerns arise from the static analysis. The complete lack of output escaping (0% properly escaped) is a critical vulnerability. This means that any data processed or displayed by the plugin is highly susceptible to cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into the user's browser. The absence of nonce checks and capability checks on its (currently nonexistent) entry points, along with no apparent taint analysis being performed, further exacerbates this risk by leaving potential future attack vectors unchecked. The bundling of Select2, while a common library, also presents a potential risk if it's an outdated version that may contain known vulnerabilities.
In conclusion, while the plugin currently presents a very small attack surface and a clean vulnerability history, the severe lack of output escaping is a glaring weakness that makes it highly insecure against XSS attacks. Developers should prioritize implementing proper output escaping mechanisms immediately. Future development should also incorporate robust authentication and authorization checks for any new entry points introduced.
Key Concerns
- 0% output escaping
- Bundled library (Select2)
- No nonce checks
- No capability checks
WP Skyscraper Security Vulnerabilities
WP Skyscraper Code Analysis
Bundled Libraries
Output Escaping
WP Skyscraper Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP Skyscraper Maintenance & Trust
Maintenance Signals
Community Trust
WP Skyscraper Alternatives
MAS Static Content
mas-static-content
MAS Static Content is a free plugin that allows you to to create a custom post type static content and use it with shortcode.
Simple Floating Menu
simple-floating-menu
Simple Floating Menu add a simple floating button with various layouts and settings.
Side Menu Lite – Sticky Floating Side Menu
side-menu-lite
Create a sticky vertical sidebar menu that enhances navigation and highlights important links on your website.
Fixed Bottom Menu
fixed-bottom-menu
Add a fixed menu. The basic menu is at the bottom, but it can also be displayed on the top, left, and right.
Catch Sticky Menu
catch-sticky-menu
Catch Sticky Menu is a lightweight, simple yet feature-rich free WordPress plugin for sticky menu that allows you to lock the menu on your website.
WP Skyscraper Developer Profile
4 plugins · 40 total installs
How We Detect WP Skyscraper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-skyscraper/js/css/colorpicker.css/wp-content/plugins/wp-skyscraper/js/js/jquery.js/wp-content/plugins/wp-skyscraper/js/js/colorpicker.js/wp-content/plugins/wp-skyscraper/js/js/jquery.js/wp-content/plugins/wp-skyscraper/js/js/colorpicker.jsHTML / DOM Fingerprints
wp_skyscraper_c2data-colorpickerjQuery$