
2MB Autocode Security & Risk Analysis
wordpress.org/plugins/2mb-autocodeThis plugin allows you to place predetermined text/html/php at the top or bottom of posts.
Is 2MB Autocode Safe to Use in 2026?
Generally Safe
Score 85/1002MB Autocode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "2mb-autocode" v1.2.6 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of identified attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events, especially those without authentication checks, suggests a limited exposure to common attack vectors. Furthermore, the code signals indicate good practices with 100% of SQL queries using prepared statements and the presence of nonce and capability checks, which are crucial for securing WordPress operations. The lack of identified dangerous functions, file operations, or external HTTP requests also contributes to its favorable security profile.
However, a notable concern is the 50% rate of improperly escaped output. This means that out of the four identified output points, two are not properly sanitized. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without adequate escaping. The absence of taint analysis results is not necessarily a negative, but it limits the ability to identify complex data flow vulnerabilities. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong indicator of a well-maintained and secure code base over time.
In conclusion, "2mb-autocode" v1.2.6 demonstrates strengths in secure coding practices, particularly in its handling of database interactions and access control. The primary area for improvement lies in ensuring all output is properly escaped to mitigate potential XSS risks. The clean vulnerability history is a significant positive, suggesting a low risk of past security flaws. The overall risk is low, with the primary concern being the unescaped output.
Key Concerns
- Output not properly escaped
2MB Autocode Security Vulnerabilities
2MB Autocode Code Analysis
Output Escaping
2MB Autocode Attack Surface
WordPress Hooks 6
Maintenance & Trust
2MB Autocode Maintenance & Trust
Maintenance Signals
Community Trust
2MB Autocode Alternatives
Code Widget
code-widget
Code widget help to add Short Code, PHP Code, HTML, and Simple Text in widget.
Append extensions on Pages
append-extensions-on-pages
This plugin helps to appends .html or .asp or .htm etc on the wordpress pages when used with permalink.
Dot html,php,xml etc pages
dot-htmlphpxml-etc-pages
Dot html,php,xml etc pages This plugin create any format of pages.
Safe PHP Code Widget
safe-php-code-widget
Adds a secure and simple widget in which you can use PHP and JavaScript code. Also you can use unfiltered HTML or just Text. Admin Use Only.
Custom HTML/PHP Post Templates
html-php-pages-and-posts
Use your HTML or PHP files for any page or post.
2MB Autocode Developer Profile
1 plugin · 100 total installs
How We Detect 2MB Autocode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[php][/php]