
Allow HTML in Category Descriptions Security & Risk Analysis
wordpress.org/plugins/allow-html-in-category-descriptionsThis plugin allows you to use unfiltered HTML in your category descriptions by disabling selected WordPress filters.
Is Allow HTML in Category Descriptions Safe to Use in 2026?
Mostly Safe
Score 78/100Allow HTML in Category Descriptions is generally safe to use. 1 past CVE were resolved. Keep it updated.
The plugin "allow-html-in-category-descriptions" v1.2.5 presents a mixed security posture. On one hand, the static analysis reveals excellent security practices within the current version, with no identified dangerous functions, all SQL queries using prepared statements, and all outputs properly escaped. The absence of an attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events is also a strong positive indicator. However, a significant concern arises from the vulnerability history, which shows one known unpatched medium severity vulnerability related to Cross-Site Scripting (XSS). The fact that this vulnerability is recent and remains unpatched despite good coding practices in the current version suggests a potential regression or a persistent flaw that hasn't been fully addressed. The presence of a capability check is noted, which is a good practice, but its effectiveness in mitigating the identified XSS vulnerability is questionable given its history. In conclusion, while the current codebase appears robust against common static analysis threats, the unpatched XSS vulnerability is a critical weakness that demands immediate attention and overshadows the otherwise positive security attributes.
Key Concerns
- Unpatched CVE
Allow HTML in Category Descriptions Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Allow HTML in Category Descriptions <= 1.2.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via Category Descriptions
Allow HTML in Category Descriptions Code Analysis
Allow HTML in Category Descriptions Attack Surface
WordPress Hooks 2
Maintenance & Trust
Allow HTML in Category Descriptions Maintenance & Trust
Maintenance Signals
Community Trust
Allow HTML in Category Descriptions Alternatives
Post Category Filter (WP Admin)
admin-category-filter
Quickly search and filter categories and taxonomies inside the WordPress admin.
List Products By Category Widget for WooCommerce
woo-products-by-category
Display a list of all the products in a WooCommerce product category with this handy widget.
Blog Post Filter
blog-post-filter
Blog Post Filter filters frontpage posts by their categories.
Cat + Tag Filter
cat-tag-filter-widget
This plugin adds a widget to your WordPress site that gives your visitors an ability to filter all your posts by a category or/and tag.
Gallery Image Captions (GIC)
gallery-image-captions
Gallery Image Captions (GIC) allows you to customise WordPress gallery image captions.
Allow HTML in Category Descriptions Developer Profile
1 plugin · 9K total installs
How We Detect Allow HTML in Category Descriptions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.