Allow HTML in Category Descriptions Security & Risk Analysis

wordpress.org/plugins/allow-html-in-category-descriptions

This plugin allows you to use unfiltered HTML in your category descriptions by disabling selected WordPress filters.

9K active installs v1.2.5 PHP 7.0+ WP 2.5+ Updated Mar 5, 2026
categoriescategory-descriptionsfilterhtml
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEFeb 13, 2026
Safety Verdict

Is Allow HTML in Category Descriptions Safe to Use in 2026?

Mostly Safe

Score 78/100

Allow HTML in Category Descriptions is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Feb 13, 2026Updated 29d ago
Risk Assessment

The plugin "allow-html-in-category-descriptions" v1.2.5 presents a mixed security posture. On one hand, the static analysis reveals excellent security practices within the current version, with no identified dangerous functions, all SQL queries using prepared statements, and all outputs properly escaped. The absence of an attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events is also a strong positive indicator. However, a significant concern arises from the vulnerability history, which shows one known unpatched medium severity vulnerability related to Cross-Site Scripting (XSS). The fact that this vulnerability is recent and remains unpatched despite good coding practices in the current version suggests a potential regression or a persistent flaw that hasn't been fully addressed. The presence of a capability check is noted, which is a good practice, but its effectiveness in mitigating the identified XSS vulnerability is questionable given its history. In conclusion, while the current codebase appears robust against common static analysis threats, the unpatched XSS vulnerability is a critical weakness that demands immediate attention and overshadows the otherwise positive security attributes.

Key Concerns

  • Unpatched CVE
Vulnerabilities
1

Allow HTML in Category Descriptions Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-0693medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Allow HTML in Category Descriptions <= 1.2.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via Category Descriptions

Feb 13, 2026Unpatched
Code Analysis
Analyzed Mar 16, 2026

Allow HTML in Category Descriptions Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Allow HTML in Category Descriptions Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninithtml-in-category-descriptions.php:16
filterplugin_row_metahtml-in-category-descriptions.php:34
Maintenance & Trust

Allow HTML in Category Descriptions Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version7.0
Downloads122K

Community Trust

Rating100/100
Number of ratings41
Active installs9K
Developer Profile

Allow HTML in Category Descriptions Developer Profile

Arno Esterhuizen

1 plugin · 9K total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Allow HTML in Category Descriptions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Allow HTML in Category Descriptions