
Cleanup HTML Security & Risk Analysis
wordpress.org/plugins/clean-htmlAdds a button to your classic editor visual toolbar that when clicked strips all div, 'table', span tags from your post HTML code -- those a …
Is Cleanup HTML Safe to Use in 2026?
Generally Safe
Score 85/100Cleanup HTML has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'clean-html' v1.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly reduces the attack surface. Furthermore, the code shows excellent practices regarding dangerous functions, SQL queries (all prepared), and output escaping, with 100% of all analyzed aspects being secure. The vulnerability history is also clean, with no recorded CVEs, indicating a well-maintained and secure plugin over time.
While the plugin appears very secure on the surface, the lack of any taint analysis flows makes it impossible to definitively rule out potential vulnerabilities that might arise from complex data interactions. The presence of two capability checks is a positive sign, but without knowing the context of these checks, it's difficult to assess their effectiveness fully. The bundling of TinyMCE, while common, could be a minor concern if the bundled version is outdated and has known vulnerabilities, though this is not explicitly stated in the analysis.
Overall, 'clean-html' v1.1 appears to be a robustly secured plugin with a minimal attack surface and no known vulnerabilities. The excellent adherence to secure coding practices is a significant strength. The only areas for potential, though unconfirmed, concern would be if the taint analysis revealed hidden issues or if the bundled TinyMCE library is outdated. However, based solely on the provided data, the plugin's security is very high.
Key Concerns
- Bundled library with potential for known vulnerabilities
Cleanup HTML Security Vulnerabilities
Cleanup HTML Code Analysis
Bundled Libraries
Cleanup HTML Attack Surface
WordPress Hooks 5
Maintenance & Trust
Cleanup HTML Maintenance & Trust
Maintenance Signals
Community Trust
Cleanup HTML Alternatives
Black Studio TinyMCE Widget
black-studio-tinymce-widget
The visual editor widget for WordPress.
Visual Term Description Editor
visual-term-description-editor
Replaces the plain-text category and tag description editor with a visual editor.
Advanced TinyMCE Configuration
advanced-tinymce-configuration
Set advanced TinyMCE options for the classic block and classic editor.
Advanced Post Excerpt
advanced-post-excerpt
Replace the default Post Excerpt meta box with a superior editing experience.
Clear Floats Button
clear-floats-button
Adds clear float button to TinyMCE Editor.
Cleanup HTML Developer Profile
10 plugins · 8K total installs
How We Detect Cleanup HTML
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clean-html/tinymce/editor_plugin.js/wp-content/plugins/clean-html/cleanup-html.js/wp-content/plugins/clean-html/tinymce/editor_plugin.js/wp-content/plugins/clean-html/cleanup-html.jsHTML / DOM Fingerprints
cleanuphtml