DoC8 Security & Risk Analysis

wordpress.org/plugins/doc8

Show your documented project, user guide, or any other type of project you have that require upfront documentation with this simple but flexible inter …

0 active installs v1.0.0 PHP + WP 4+ Updated Jul 31, 2018
docsdocumentationfaqsknowledge-base
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is DoC8 Safe to Use in 2026?

Generally Safe

Score 85/100

DoC8 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin 'doc8' v1.0.0 exhibits a strong overall security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs, critical taint flows, dangerous functions, or external HTTP requests is highly positive. Furthermore, the complete lack of SQL injection vulnerabilities due to 100% prepared statement usage is a significant strength. The plugin also demonstrates good practices in not exposing significant attack surface through AJAX handlers, REST API routes, shortcodes, or cron events, with zero unprotected entry points.

However, a notable concern lies in the output escaping, where only 38% of outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without sufficient sanitization. The lack of nonce and capability checks across all entry points, though the entry points are currently zero, represents a potential future risk if the plugin's functionality expands without implementing these essential security controls. The vulnerability history is clean, but this doesn't negate the observed code-level risk of unescaped output.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

DoC8 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

DoC8 Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

DoC8 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped13 total outputs
Attack Surface

DoC8 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionplugins_loadeddoc8.php:72
actioninitdoc8.php:103
actionadmin_initdoc8.php:114
actionadmin_enqueue_scriptsdoc8.php:117
actionadmin_menudoc8.php:120
actionsave_postdoc8.php:123
actionwp_enqueue_scriptsdoc8.php:127
filterpre_get_postsdoc8.php:129
filterposts_orderbydoc8.php:130
filtertemplate_includedoc8.php:132
filterget_the_archive_titledoc8.php:133
filterget_the_archive_descriptiondoc8.php:134
filterthe_contentdoc8.php:135
actionupdated_optioninc/class-doc8-settings.php:17
Maintenance & Trust

DoC8 Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 31, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

DoC8 Developer Profile

Irene

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DoC8

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/doc8/assets/css/standard.min.css/wp-content/plugins/doc8/assets/external/ace/src-min-noconflict/ace.js/wp-content/plugins/doc8/assets/js/ace-editor-config.min.js/wp-content/plugins/doc8/assets/css/admin.min.css/wp-content/plugins/doc8/assets/js/admin.min.js
Version Parameters
docu-standard?ver=docu-ace?ver=docu-editor-config?ver=doc8-admin-css?ver=doc8-admin-js?ver=

HTML / DOM Fingerprints

CSS Classes
docu-wrappage-titledoc8-adddoc8-attachmentsdoc8-toggle
Data Attributes
data-doc8-attachments
FAQ

Frequently Asked Questions about DoC8