
WP Smart Preloader Security & Risk Analysis
wordpress.org/plugins/wp-smart-preloaderA Plugin to add awesome collection of Loaders and Spinners. Delightful and performance-focused Pure CSS animations.
Is WP Smart Preloader Safe to Use in 2026?
Generally Safe
Score 92/100WP Smart Preloader has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The static analysis of wp-smart-preloader v1.15.3 reveals a generally strong security posture with no identified dangerous functions, SQL injection vulnerabilities, or file operations. The plugin also avoids external HTTP requests, which is a positive sign. The high percentage of properly escaped output further indicates good coding practices for preventing cross-site scripting.
However, the complete absence of capability checks and nonce checks is a significant concern, especially given the plugin's vulnerability history. While there are currently no unpatched CVEs, the fact that the plugin has had one CVE in the past, specifically related to Cross-site Scripting, highlights the potential for issues in how user input is handled, even if current static analysis did not detect critical taint flows.
In conclusion, while the code itself appears to be relatively clean and avoids common pitfalls like raw SQL or dangerous functions, the lack of explicit authorization and integrity checks (capability and nonce checks) presents a latent risk. The historical CVE suggests that vulnerabilities can arise, and without these fundamental security mechanisms, the plugin is more susceptible to exploitation if such a vulnerability were to be reintroduced or if other plugins interact with it in an insecure manner. The plugin's strengths lie in its internal code quality, but its weaknesses are in its integration security and lack of defensive layers against common web attacks.
Key Concerns
- No capability checks found
- No nonce checks found
- 1 medium severity CVE in history
- Output escaping not 100%
WP Smart Preloader Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Smart Preloader <= 1.15 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Smart Preloader Release Timeline
WP Smart Preloader Code Analysis
Output Escaping
WP Smart Preloader Attack Surface
WordPress Hooks 6
Maintenance & Trust
WP Smart Preloader Maintenance & Trust
Maintenance Signals
Community Trust
WP Smart Preloader Alternatives
Pressfore Preloaders
pressfore-preloaders
Best free wordpress preloaders plugin for creating stunning spinners/preloaders which will be displayed while your page is loading.
Safelayout Cute Preloader – CSS3 WordPress Preloader
safelayout-cute-preloader
Easily add a pure CSS animated preloader to your WordPress website.
WP Fakeloader
wp-fakeloader
WP Fakeloader is a simple and customizable wordpress preloader plugin based on fakeloader js.
HF-Preloader-Awesome
hf-preloader-awesome
This plugin will make awesome style when your Webpage loading. It will help you to stay visitor in your website and also increase your traffic.
WP Preloader
wp-preloader
WP Preloader is a simple and customizable wordpress preloader plugin. Very easy to use.
WP Smart Preloader Developer Profile
5 plugins · 10K total installs
How We Detect WP Smart Preloader
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-smart-preloader/assets/css/wsp-admin-preloader.css/wp-content/plugins/wp-smart-preloader/assets/css/wsp-front-preloader.css/wp-content/plugins/wp-smart-preloader/assets/css/wsp-smart-preload-style.css/wp-content/plugins/wp-smart-preloader/assets/js/wsp-admin-script.js/wp-content/plugins/wp-smart-preloader/assets/js/wsp-main-script.jshttps://cdnjs.cloudflare.com/ajax/libs/ace/1.2.3/ace.jswp-smart-preloader/assets/css/wsp-admin-preloader.css?ver=wp-smart-preloader/assets/css/wsp-front-preloader.css?ver=wp-smart-preloader/assets/css/wsp-smart-preload-style.css?ver=wp-smart-preloader/assets/js/wsp-admin-script.js?ver=wp-smart-preloader/assets/js/wsp-main-script.js?ver=HTML / DOM Fingerprints
wp-smart-bodywsp_obj