
Djot Markup Security & Risk Analysis
wordpress.org/plugins/djot-markupDjot markup language support for WordPress. A modern, cleaner alternative to Markdown.
Is Djot Markup Safe to Use in 2026?
Generally Safe
Score 100/100Djot Markup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The djot-markup plugin version 1.5.5 demonstrates a generally strong security posture, with several good practices evident in its code. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests are significant strengths. The high percentage of properly escaped output further contributes to a reduced risk of cross-site scripting (XSS) attacks. However, the presence of one REST API route without a permission callback represents a notable concern, creating an unprotected entry point that could potentially be exploited by unauthenticated users. The lack of any recorded vulnerability history is a positive indicator, suggesting the plugin has historically been maintained with security in mind. Nevertheless, the unprotected REST API route is a specific risk that needs immediate attention, as even without known historical vulnerabilities, an unprotected endpoint is an open invitation for potential abuse. Overall, while the plugin has a solid foundation, this single unprotected entry point detracts from its otherwise good security profile.
Key Concerns
- Unprotected REST API route
- No nonce checks
- Limited capability checks
Djot Markup Security Vulnerabilities
Djot Markup Release Timeline
Djot Markup Code Analysis
Output Escaping
Djot Markup Attack Surface
REST API Routes 4
WordPress Hooks 17
Maintenance & Trust
Djot Markup Maintenance & Trust
Maintenance Signals
Community Trust
Djot Markup Alternatives
SyntaxHighlighter Evolved
syntaxhighlighter
Easily post syntax-highlighted code to your site without having to modify the code at all. As seen on WordPress.com.
HTML Validation
html-validation
The HTML Validation Plugin runs in the background, identifies and reports HTML validation errors on your website. Once activated, the HTML Validation …
WP-Markdown
wp-markdown
Allows Markdown to be enabled in posts, comments and bbPress forums.
Code Markup
code-markup
Code Markup is a WordPress plugin that makes it easy to include program code samples in your posts.
Simple Code Block
simple-code-block
A simple block to insert code into Gutenberg.
Djot Markup Developer Profile
1 plugin · 0 total installs
How We Detect Djot Markup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/djot-markup/assets/js/editor-torchlight.js/wp-content/plugins/djot-markup/assets/js/editor-torchlight.jsdjot-markup/assets/js/editor-torchlight.js?ver=HTML / DOM Fingerprints
<!-- wp:wpdjot/djot --><!-- wp:wp-djot/djot -->window.wpdjot_version/wp-json/wpdjot/v1/render/wp-json/wpdjot/v1/convert-markdown/wp-json/wpdjot/v1/convert-html