
DoC8 Security & Risk Analysis
wordpress.org/plugins/doc8Show your documented project, user guide, or any other type of project you have that require upfront documentation with this simple but flexible inter …
Is DoC8 Safe to Use in 2026?
Generally Safe
Score 85/100DoC8 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'doc8' v1.0.0 exhibits a strong overall security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs, critical taint flows, dangerous functions, or external HTTP requests is highly positive. Furthermore, the complete lack of SQL injection vulnerabilities due to 100% prepared statement usage is a significant strength. The plugin also demonstrates good practices in not exposing significant attack surface through AJAX handlers, REST API routes, shortcodes, or cron events, with zero unprotected entry points.
However, a notable concern lies in the output escaping, where only 38% of outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without sufficient sanitization. The lack of nonce and capability checks across all entry points, though the entry points are currently zero, represents a potential future risk if the plugin's functionality expands without implementing these essential security controls. The vulnerability history is clean, but this doesn't negate the observed code-level risk of unescaped output.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
DoC8 Security Vulnerabilities
DoC8 Release Timeline
DoC8 Code Analysis
Output Escaping
DoC8 Attack Surface
WordPress Hooks 14
Maintenance & Trust
DoC8 Maintenance & Trust
Maintenance Signals
Community Trust
DoC8 Alternatives
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor
betterdocs
A full-featured documentation plugin including AI writing assistance to create knowledge bases, docs, FAQs, wikis, and more with easy drag & drop UI.
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
wedocs
Build a powerful documentation hub with an AI-powered knowledge base, docs, wiki tools, and an AI chatbot to help users find answers instantly.
Knowledge Base documentation & wiki plugin – BasePress Docs
basepress
Easily create & manage documentation. Reduce support tickets & scale your customer support workload. This simple plugin works with any theme.
Smart Docs
smart-docs
Knowledge Base & Documentation Plugin for WordPress.
Knowledge Base CPT
knowledge-base-cpt
Enables a 'knowledge base post' type and 'section' taxonomy.
DoC8 Developer Profile
1 plugin · 0 total installs
How We Detect DoC8
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/doc8/assets/css/standard.min.css/wp-content/plugins/doc8/assets/external/ace/src-min-noconflict/ace.js/wp-content/plugins/doc8/assets/js/ace-editor-config.min.js/wp-content/plugins/doc8/assets/css/admin.min.css/wp-content/plugins/doc8/assets/js/admin.min.jsdocu-standard?ver=docu-ace?ver=docu-editor-config?ver=doc8-admin-css?ver=doc8-admin-js?ver=HTML / DOM Fingerprints
docu-wrappage-titledoc8-adddoc8-attachmentsdoc8-toggledata-doc8-attachments