
Dot html,php,xml etc pages Security & Risk Analysis
wordpress.org/plugins/dot-htmlphpxml-etc-pagesDot html,php,xml etc pages This plugin create any format of pages.
Is Dot html,php,xml etc pages Safe to Use in 2026?
High Risk
Score 42/100Dot html,php,xml etc pages carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The 'dot-htmlphpxml-etc-pages' plugin v1.0 presents a mixed security picture. On the positive side, the plugin boasts a seemingly small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, all of which are unprotected. Furthermore, it utilizes prepared statements for all SQL queries and includes a nonce check, demonstrating an awareness of some fundamental security practices. However, significant concerns arise from the static analysis. Critically, 100% of output is not properly escaped, which is a major red flag for Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history. The presence of one flow with an unsanitized path in the taint analysis, while not critical or high severity, still indicates a potential weakness in input handling.
The plugin's vulnerability history is particularly alarming. With two known medium-severity CVEs, both currently unpatched, and a common vulnerability type being Cross-Site Scripting (XSS), it strongly suggests a recurring pattern of insecure output handling. The fact that these vulnerabilities are not only present but also remain unpatched indicates a lack of ongoing security maintenance and a high likelihood of exploitation. While the limited attack surface is a positive, the unpatched XSS vulnerabilities and the unescaped output create a substantial risk, overshadowing the good practices observed in other areas. This plugin should be treated with extreme caution due to the high probability of exploitable XSS flaws.
Key Concerns
- Two unpatched CVEs (medium severity)
- 0% output properly escaped
- Flow with unsanitized path
Dot html,php,xml etc pages Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Dot html,php,xml etc pages <= 1.0 - Reflected Cross-Site Scripting
Dot html,php,xml etc pages <= 1.0 - Reflected Cross-Site Scripting
Dot html,php,xml etc pages Code Analysis
Output Escaping
Data Flow Analysis
Dot html,php,xml etc pages Attack Surface
WordPress Hooks 5
Maintenance & Trust
Dot html,php,xml etc pages Maintenance & Trust
Maintenance Signals
Community Trust
Dot html,php,xml etc pages Alternatives
Append extensions on Pages
append-extensions-on-pages
This plugin helps to appends .html or .asp or .htm etc on the wordpress pages when used with permalink.
Custom HTML/PHP Post Templates
html-php-pages-and-posts
Use your HTML or PHP files for any page or post.
HTML Page Sitemap
html-sitemap
Adds an HTML (Not XML) sitemap of your pages (not posts) by entering the shortcode [html_sitemap], perfect for those who use WordPress as a CMS.
Code Widget
code-widget
Code widget help to add Short Code, PHP Code, HTML, and Simple Text in widget.
WP Simple HTML Sitemap
wp-simple-html-sitemap
Using Simple HTML Sitemap plugin, you can add HTML Sitemap anywhere on the website using Shortcode.
Dot html,php,xml etc pages Developer Profile
3 plugins · 210 total installs
How We Detect Dot html,php,xml etc pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
name="dot_pages_enable"name="dot_pages_slug"name="dot_pages_mode"id="dot_pages_slug"