HTML Block with Highlighting Security & Risk Analysis

wordpress.org/plugins/html-block-with-highlighting

HTML Block with Highlighting is a WordPress plugin which adds a new HTML Block with syntax highlighting to the Gutenberg editor.

10 active installs v1.0.0 PHP 7.2+ WP 5.3+ Updated Mar 30, 2020
editorhtmlhtml-blocksyntax-highlighting
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HTML Block with Highlighting Safe to Use in 2026?

Generally Safe

Score 85/100

HTML Block with Highlighting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "html-block-with-highlighting" v1.0.0 plugin demonstrates a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, SQL queries without prepared statements, unescaped output, file operations, or external HTTP requests is a positive indicator. Furthermore, the lack of vulnerabilities in the plugin's history suggests a commitment to security by its developers. The total absence of entry points (AJAX, REST API, shortcodes, cron events) is also a significant strength, as it minimizes the plugin's attack surface considerably.

However, the complete lack of entry points might also indicate that the plugin's functionality is extremely limited or perhaps not yet fully implemented. It's unusual for a plugin to have zero entry points in its static analysis. While this currently prevents any direct attack vectors, it also means there are no explicit capability checks or nonce checks present. If functionality is ever added that requires user interaction or modification of data, the current lack of these security measures could become a significant concern. The taint analysis showing zero flows is good, but this is contingent on the analysis covering all potential code paths, which might be limited given the zero entry points.

In conclusion, the plugin "html-block-with-highlighting" v1.0.0 currently exhibits a very secure profile due to its minimal attack surface and the absence of common vulnerabilities in its code and history. The developers appear to be following good practices where applicable. The primary weakness lies in the potential for future vulnerabilities if functionality is added without implementing proper authentication and authorization checks, given their current absence. This plugin is safe to use as is, but future development should be closely monitored for security implementations.

Vulnerabilities
None known

HTML Block with Highlighting Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

HTML Block with Highlighting Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

HTML Block with Highlighting Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

HTML Block with Highlighting Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitindex.php:62
Maintenance & Trust

HTML Block with Highlighting Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedMar 30, 2020
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

HTML Block with Highlighting Developer Profile

cssdaily

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HTML Block with Highlighting

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/html-block-with-highlighting/build/index.js/wp-content/plugins/html-block-with-highlighting/build/codemirror.css/wp-content/plugins/html-block-with-highlighting/build/codemirror-ayu-mirage.css/wp-content/plugins/html-block-with-highlighting/build/codemirror-show-hint.css/wp-content/plugins/html-block-with-highlighting/build/html-block-with-highlighting.css
Script Paths
/wp-content/plugins/html-block-with-highlighting/build/index.js
Version Parameters
html-block-with-highlighting?ver=codemirror.css?ver=codemirror-ayu-mirage.css?ver=codemirror-show-hint.css?ver=html-block-with-highlighting.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about HTML Block with Highlighting