
Kolossum – cdnJS for WordPress Security & Risk Analysis
wordpress.org/plugins/wpcdnkolossAdd search and include functionality for the cdnjs.com libraries
Is Kolossum – cdnJS for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Kolossum – cdnJS for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wpcdnkoloss v0.5 plugin exhibits a mixed security posture. On the positive side, it has a relatively small attack surface with all identified entry points having nonce checks, and there are no known vulnerabilities or CVEs recorded. This suggests a potential awareness of security practices in terms of external threats and common exploits.
However, significant concerns arise from the static code analysis. The complete absence of capability checks for AJAX handlers is a major vulnerability, as it implies that any authenticated user, regardless of their role, could potentially trigger these handlers. Furthermore, the fact that 100% of SQL queries are not using prepared statements is a critical risk, opening the door to SQL injection attacks. The high percentage of improperly escaped output also suggests a risk of Cross-Site Scripting (XSS) vulnerabilities.
While the plugin's vulnerability history is clean, this can be misleading if the code analysis reveals inherent weaknesses. The lack of capability checks and unprepared SQL queries represent foundational security flaws that are more concerning than a lack of recorded past exploits. The absence of taint analysis issues with sanitization is a positive sign, but it does not negate the direct code vulnerabilities identified.
Key Concerns
- AJAX handlers lack capability checks
- SQL queries not using prepared statements
- Low percentage of output escaping
Kolossum – cdnJS for WordPress Security Vulnerabilities
Kolossum – cdnJS for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Kolossum – cdnJS for WordPress Attack Surface
AJAX Handlers 6
WordPress Hooks 3
Maintenance & Trust
Kolossum – cdnJS for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Kolossum – cdnJS for WordPress Alternatives
WP jQuery Plus
wp-jquery-plus
Loads jQuery from a CDN using the exact version as your current WordPress install
WP cdnjs
wp-cdnjs
Integrates easily CSS and JavaScript Libraries hosted by CDNjs.com. Browse, select version and sub-assets to fit your needs.
CDNJS for WordPress
cdnjs
Replace Javascript and CSS libraries on your WordPress site with CloudFlare's FREE CDN
W3 Total Cache
w3-total-cache
Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.
SpeedyCache – Cache, Optimization, Performance
speedycache
SpeedyCache is a WordPress cache plugin that helps you improve performance of your WordPress site by caching, minifying, and compressing your website.
Kolossum – cdnJS for WordPress Developer Profile
1 plugin · 0 total installs
How We Detect Kolossum – cdnJS for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpcdnkoloss//wp-content/plugins/wpcdnkoloss/js/wpcdnkoloss-admin.js/wp-content/plugins/wpcdnkoloss/js/wpcdnkoloss-public.jswpcdnkoloss/style.css?ver=wpcdnkoloss/script.js?ver=HTML / DOM Fingerprints
wpcdnkolossWpCdnKoloss