hRecipe Support for Editor Security & Risk Analysis

wordpress.org/plugins/hrecipe-plugin-for-wordpress

This is a plugin to allow the easy entry of microformat content for recipes (i.e. the hRecipe microformat) in WordPress pages and posts.

10 active installs v0.2.4.2 PHP + WP 2.7.1+ Updated Apr 27, 2009
editorhrecipe
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is hRecipe Support for Editor Safe to Use in 2026?

Generally Safe

Score 85/100

hRecipe Support for Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

The hrecipe-plugin-for-wordpress v0.2.4.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the clean taint analysis, with zero critical or high severity flows, are positive indicators. Furthermore, the plugin utilizes prepared statements for all SQL queries, which is a crucial security best practice. The fact that there are no file operations or external HTTP requests also reduces potential attack vectors.

However, a significant concern arises from the complete lack of output escaping. With 12 identified output points, and 0% being properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed to users could be manipulated by an attacker to inject malicious scripts. Additionally, the complete absence of nonce checks and capability checks on potential entry points (even though the attack surface is reported as 0) indicates a lack of robust access control and data integrity measures. The presence of the TinyMCE bundled library, while common, could also pose a risk if it's an outdated version.

In conclusion, while the plugin avoids common pitfalls like raw SQL queries and known vulnerabilities, the severe lack of output escaping is a critical weakness that needs immediate attention. The absence of comprehensive authorization checks also warrants review. The plugin demonstrates good database security practices but falters significantly in protecting against client-side attacks and ensuring proper access control.

Key Concerns

  • 0% output escaping
  • No nonce checks
  • No capability checks
  • Bundled library (TinyMCE) potentially outdated
Vulnerabilities
None known

hRecipe Support for Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

hRecipe Support for Editor Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

hRecipe Support for Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

0% escaped12 total outputs
Attack Surface

hRecipe Support for Editor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_footerhrecipe.php:40
actionwp_headhrecipe.php:41
actionmarker_csshrecipe.php:42
actioninithrecipe.php:43
actionadmin_menuhrecipe.php:44
filtermce_external_pluginshrecipe.php:49
filtermce_buttons_3hrecipe.php:50
Maintenance & Trust

hRecipe Support for Editor Maintenance & Trust

Maintenance Signals

WordPress version tested2.7.1
Last updatedApr 27, 2009
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

hRecipe Support for Editor Developer Profile

Dave Doolin

3 plugins · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect hRecipe Support for Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hrecipe-plugin-for-wordpress/tinymceplugin/editor_plugin.js/wp-content/plugins/hrecipe-plugin-for-wordpress/starfull.gif/wp-content/plugins/hrecipe-plugin-for-wordpress/starhalf.gif/wp-content/plugins/hrecipe-plugin-for-wordpress/starempty.gif/wp-content/plugins/hrecipe-plugin-for-wordpress/hrecipeinput.php
Script Paths
/wp-content/plugins/hrecipe-plugin-for-wordpress/tinymceplugin/editor_plugin.js

HTML / DOM Fingerprints

CSS Classes
hrecipefnurlsummaryingredientsingredientinstructionsculinarytradition+3 more
Data Attributes
class="hrecipe"class="fn"class="url"class="summary"class="ingredients"class="ingredient"+5 more
JS Globals
hrecipe_from_guiedInsertHRecipeedInsertHRecipeCodehrecipe_qttoolbaredInsertHRecipeAbortedInsertHRecipeStars+6 more
FAQ

Frequently Asked Questions about hRecipe Support for Editor