
hRecipe Support for Editor Security & Risk Analysis
wordpress.org/plugins/hrecipe-plugin-for-wordpressThis is a plugin to allow the easy entry of microformat content for recipes (i.e. the hRecipe microformat) in WordPress pages and posts.
Is hRecipe Support for Editor Safe to Use in 2026?
Generally Safe
Score 85/100hRecipe Support for Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The hrecipe-plugin-for-wordpress v0.2.4.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the clean taint analysis, with zero critical or high severity flows, are positive indicators. Furthermore, the plugin utilizes prepared statements for all SQL queries, which is a crucial security best practice. The fact that there are no file operations or external HTTP requests also reduces potential attack vectors.
However, a significant concern arises from the complete lack of output escaping. With 12 identified output points, and 0% being properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed to users could be manipulated by an attacker to inject malicious scripts. Additionally, the complete absence of nonce checks and capability checks on potential entry points (even though the attack surface is reported as 0) indicates a lack of robust access control and data integrity measures. The presence of the TinyMCE bundled library, while common, could also pose a risk if it's an outdated version.
In conclusion, while the plugin avoids common pitfalls like raw SQL queries and known vulnerabilities, the severe lack of output escaping is a critical weakness that needs immediate attention. The absence of comprehensive authorization checks also warrants review. The plugin demonstrates good database security practices but falters significantly in protecting against client-side attacks and ensuring proper access control.
Key Concerns
- 0% output escaping
- No nonce checks
- No capability checks
- Bundled library (TinyMCE) potentially outdated
hRecipe Support for Editor Security Vulnerabilities
hRecipe Support for Editor Release Timeline
hRecipe Support for Editor Code Analysis
Bundled Libraries
Output Escaping
hRecipe Support for Editor Attack Surface
WordPress Hooks 7
Maintenance & Trust
hRecipe Support for Editor Maintenance & Trust
Maintenance Signals
Community Trust
hRecipe Support for Editor Alternatives
hRecipe
hrecipe
Use hRecipe for creating Google Rich Snippets, for leveraging SEO results, and for attractively displaying your recipes.
Elementor Website Builder – more than just a page builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, Atomic Editor, pixel perfect design, global and reusable style systems, mobile r …
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
hRecipe Support for Editor Developer Profile
3 plugins · 90 total installs
How We Detect hRecipe Support for Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hrecipe-plugin-for-wordpress/tinymceplugin/editor_plugin.js/wp-content/plugins/hrecipe-plugin-for-wordpress/starfull.gif/wp-content/plugins/hrecipe-plugin-for-wordpress/starhalf.gif/wp-content/plugins/hrecipe-plugin-for-wordpress/starempty.gif/wp-content/plugins/hrecipe-plugin-for-wordpress/hrecipeinput.php/wp-content/plugins/hrecipe-plugin-for-wordpress/tinymceplugin/editor_plugin.jsHTML / DOM Fingerprints
hrecipefnurlsummaryingredientsingredientinstructionsculinarytradition+3 moreclass="hrecipe"class="fn"class="url"class="summary"class="ingredients"class="ingredient"+5 morehrecipe_from_guiedInsertHRecipeedInsertHRecipeCodehrecipe_qttoolbaredInsertHRecipeAbortedInsertHRecipeStars+6 more