WP SyntaxHighlighter Theme Advance Security & Risk Analysis

wordpress.org/plugins/wp-syntaxhighlighter-theme

This plugin allow you to add and custom SyntaxHighlighter\'s theme.

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Sep 17, 2014
syntaxhighlighter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP SyntaxHighlighter Theme Advance Safe to Use in 2026?

Generally Safe

Score 85/100

WP SyntaxHighlighter Theme Advance has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin "wp-syntaxhighlighter-theme" v1.0.0 demonstrates a mixed security posture. On the positive side, it has a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, all of which would typically be common entry points for attackers. Furthermore, there are no known CVEs associated with this plugin, and it has a clean vulnerability history, suggesting a generally stable and well-maintained codebase in that regard. However, significant concerns arise from the static code analysis. The complete lack of capability checks and the presence of raw SQL queries without prepared statements are critical weaknesses. While the plugin doesn't appear to have critical taint flows leading to severe vulnerabilities like remote code execution or SQL injection directly, the high number of flows with unsanitized paths (4 out of 4 analyzed) combined with the unescaped output (only 23% properly escaped) points to a substantial risk of cross-site scripting (XSS) and potentially other injection-based vulnerabilities, especially if user-supplied data is involved in these unsanitized flows. The absence of capability checks means that any functionality, however limited, might be accessible to unauthenticated users if an entry point were to be discovered or if the plugin's internal logic could be manipulated. This combination of factors presents a notable risk that outweighs the otherwise clean attack surface and vulnerability history.

Key Concerns

  • SQL queries without prepared statements
  • High percentage of unsanitized paths in taint flows
  • Low percentage of properly escaped output
  • No capability checks on entry points
Vulnerabilities
None known

WP SyntaxHighlighter Theme Advance Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP SyntaxHighlighter Theme Advance Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
0 prepared
Unescaped Output
17
5 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared4 total queries

Output Escaping

23% escaped22 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
form_handler (scb\AdminPage.php:196)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP SyntaxHighlighter Theme Advance Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionadmin_noticescore.php:12
actionwp_enqueue_scriptsinc\SHT_Theme.php:29
actionadmin_enqueue_scriptsinc\SHT_Theme.php:30
filtersyntaxhighlighter_themesinc\SHT_Theme.php:31
action_admin_menuscb\AdminPage.php:58
actionadmin_initscb\AdminPage.php:116
actionadmin_noticesscb\AdminPage.php:117
actionadmin_menuscb\AdminPage.php:120
filtercontextual_helpscb\AdminPage.php:121
actionadmin_noticesscb\AdminPage.php:215
filtercron_schedulesscb\Cron.php:57
actionactivate_pluginscb\load.php:32
actionplugins_loadedscb\load.php:38
actionload-post.phpscb\PostMetabox.php:30
actionload-post-new.phpscb\PostMetabox.php:31
actionadd_meta_boxesscb\PostMetabox.php:44
actionsave_postscb\PostMetabox.php:45
actionwidgets_initscb\Widget.php:13
Maintenance & Trust

WP SyntaxHighlighter Theme Advance Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 17, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP SyntaxHighlighter Theme Advance Developer Profile

Duoc Nguyen

5 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP SyntaxHighlighter Theme Advance

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-syntaxhighlighter-theme/themes/shThemeSenViet.css
Version Parameters
wp-syntaxhighlighter-theme/themes/shThemeSenViet.css?ver=

HTML / DOM Fingerprints

Data Attributes
slug="senviet"
FAQ

Frequently Asked Questions about WP SyntaxHighlighter Theme Advance