
Always Edit In HTML Security & Risk Analysis
wordpress.org/plugins/always-edit-in-htmlAlways opens up a specific page or post in HTML mode to preserve HTML code (classic editor only).
Is Always Edit In HTML Safe to Use in 2026?
Generally Safe
Score 92/100Always Edit In HTML has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'always-edit-in-html' v2.4.6 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs and a complete lack of critical or high-severity vulnerabilities in its history suggest a well-maintained and secure plugin. Furthermore, the static analysis reveals a remarkably small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without appropriate authentication or permission checks. The code also shows positive signs such as the complete absence of dangerous functions and all SQL queries utilizing prepared statements, indicating a good understanding of secure coding practices regarding database interactions.
However, the analysis does highlight a significant concern: a 100% rate of unescaped output across the three identified output points. This means that any data processed by the plugin and then displayed to users or in the admin interface is not being properly sanitized. This could lead to Cross-Site Scripting (XSS) vulnerabilities if the plugin handles or displays user-supplied data without sanitization. While the plugin has one nonce check and two capability checks, the lack of output escaping is a critical weakness that could be exploited. Despite the clean vulnerability history, this oversight presents a direct and exploitable risk that should be addressed.
Key Concerns
- All output not properly escaped
Always Edit In HTML Security Vulnerabilities
Always Edit In HTML Code Analysis
Output Escaping
Always Edit In HTML Attack Surface
WordPress Hooks 4
Maintenance & Trust
Always Edit In HTML Maintenance & Trust
Maintenance Signals
Community Trust
Always Edit In HTML Alternatives
Contact Form 7 Syntax Highlighting
cf7-ace-syntax-highlighting
Adds syntax higlighting to the Contact Form 7 admin screens. Requires the Contact Form 7 plugin.
HTML Editor for Contact Form 7
cf7-coder
Add HTML editor to Contact Form 7 with code highlighter and extended form options.
Protect schema.org markup in HTML editor
protect-schemaorg-markup-in-html-editor
Easy tool to stop HTML editor from removing schema.org/microdata tags from post or page content.
HTML Mode Locker
html-mode-locker
Adds and option to lock post editor in HTML Mode on selected post types on per-item basis.
Syntax Highlight
syntax-highlight
Syntax Highlighting in WordPress Plugins and Themes Editor.
Always Edit In HTML Developer Profile
5 plugins · 3K total installs
How We Detect Always Edit In HTML
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/always-edit-in-html/images/zeropointdevelopment-mark.pngHTML / DOM Fingerprints
switch-tmcename="always_edit_in_html"id="always_edit_in_html"name="always_edit_in_html_noncename"