• This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn more.

XF 1.5 How safe are third party skins?


Active member
I am just wondering how safe third party skins are. Can they present any kind of security risk to a Xenforo board or open up holes for potential exploit? Or do skins basically just stay away form the nuts and bolts of the XF code?

Just wondering...

Chris D

XenForo developer
Staff member
The biggest risks with regards to third party styles is the inclusion of potential XSS (cross site scripting) type vulnerabilities from third party JS libraries that are often included.

That said, styles in themselves should stay away from the XF code itself. Some styles include add-ons which may provide other features but these are usually optional and they are always a separate thing to install.

All things considered, you should be pretty safe. I would urge you, however, to stick to styles that are available in our Resource Manager from authors who are well known within the community. You will be able to see feedback from other users and check how often their work is kept up to date, etc.