
HTML代码优化工具 Security & Risk Analysis
wordpress.org/plugins/clear-html-tagsHTML代码优化工具(Clear HTML Tags)是一款站长实用的WordPress文章编辑辅助插件,可以帮助站长快速实现删除HTML代码不需要的常见HTML标签及标签属性,常用的代码格式优化。
Is HTML代码优化工具 Safe to Use in 2026?
Generally Safe
Score 85/100HTML代码优化工具 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The clear-html-tags v1.1.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and SQL queries not using prepared statements are significant strengths. The plugin also appears to have a well-defined, albeit small, attack surface with only one AJAX handler, which benefits from a capability check, preventing direct unauthorized access. The taint analysis revealing no critical or high severity flows with unsanitized paths is also a positive indicator.
However, a notable concern is the low percentage (26%) of properly escaped output. With 27 total outputs, this means a significant number of them are likely unescaped, potentially opening the door to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted. While there are no recorded vulnerabilities in its history, this lack of historical issues could be due to the limited attack surface or simply good fortune, rather than a guarantee of future security. The absence of nonce checks on the single AJAX handler, while protected by a capability check, is also a minor weakness in defense-in-depth.
In conclusion, the plugin demonstrates good practices in several critical security areas. The primary area for improvement and attention is the consistent and proper escaping of all output. The absence of historical vulnerabilities is a positive sign, but the potential for XSS due to unescaped output remains the most significant risk identified.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks on AJAX handler
HTML代码优化工具 Security Vulnerabilities
HTML代码优化工具 Code Analysis
Output Escaping
Data Flow Analysis
HTML代码优化工具 Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
HTML代码优化工具 Maintenance & Trust
Maintenance Signals
Community Trust
HTML代码优化工具 Alternatives
XML Sitemap Generator for Google
google-sitemap-generator
Generate multiple types of sitemaps to improve SEO and get your website indexed quickly.
WP Sitemap Page
wp-sitemap-page
Add a sitemap on any of your page using the simple shortcode [wp_sitemap_page]. Improve the SEO and navigation of your website.
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Simple Sitemap – Create a Responsive HTML Sitemap
simple-sitemap
Create a HTML sitemap and preview directly inside the editor! No more complicated shortcodes. Boost the SEO performance of your WordPress site.
Mammoth .docx converter
mammoth-docx-converter
Mammoth converts semantically marked up .docx documents to simple and clean HTML, allowing pasting from Word and Google Docs without the usual mess.
HTML代码优化工具 Developer Profile
11 plugins · 17K total installs
How We Detect HTML代码优化工具
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clear-html-tags/assets/wbp_admin.css/wp-content/plugins/clear-html-tags/assets/wbui/wbui.js/wp-content/plugins/clear-html-tags/assets/wbp_admin.js/wp-content/plugins/clear-html-tags/assets/vue.min.js/wp-content/plugins/clear-html-tags/assets/wbp_setting.js/wp-content/plugins/clear-html-tags/assets/wbp_setting.css/wp-content/plugins/clear-html-tags/assets/wbp_admin.js/wp-content/plugins/clear-html-tags/assets/wbui/wbui.js/wp-content/plugins/clear-html-tags/assets/vue.min.js/wp-content/plugins/clear-html-tags/assets/wbp_setting.js/wp-content/plugins/clear-html-tags/assets/wbp_admin.css?ver=/wp-content/plugins/clear-html-tags/assets/wbui/wbui.js?ver=/wp-content/plugins/clear-html-tags/assets/wbp_admin.js?ver=/wp-content/plugins/clear-html-tags/assets/vue.min.js?ver=/wp-content/plugins/clear-html-tags/assets/wbp_setting.js?ver=/wp-content/plugins/clear-html-tags/assets/wbp_setting.css?ver=HTML / DOM Fingerprints
id="wb-cls-tag-btn"var wbcht_cnf=var _pd_code='cht-setting'cnf_cht=opt_cht=