.html for all url Security & Risk Analysis

wordpress.org/plugins/html-for-all-url

convert your url in .html easaly for post, page, custom post type ...

100 active installs v1.2 PHP + WP 4.5+ Updated Aug 3, 2017
html-to-cpthtml-to-custom-post-typehtml-to-posthtml-to-urladds-html-to-pages
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is .html for all url Safe to Use in 2026?

Generally Safe

Score 85/100

.html for all url has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "html-for-all-url" v1.2 plugin exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. Furthermore, the code demonstrates excellent adherence to secure coding practices with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The absence of file operations, external HTTP requests, nonce checks, and capability checks also contributes to a low-risk profile. The taint analysis, while identifying flows with unsanitized paths, did not flag any critical or high-severity issues, suggesting these paths might be within less sensitive areas or already mitigated by other factors not explicitly detailed.

The plugin's vulnerability history is exceptionally clean, with zero known CVEs of any severity. This lack of historical vulnerabilities, combined with the current analysis, indicates a well-maintained and secure codebase. The absence of common vulnerability types further reinforces this assessment. While the presence of "flows with unsanitized paths" is a minor concern, the lack of critical or high severity findings in the taint analysis and the overall absence of exploitable entry points significantly mitigate this risk. In conclusion, "html-for-all-url" v1.2 appears to be a highly secure plugin with no immediate security risks based on the provided data.

Key Concerns

  • Flows with unsanitized paths detected
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

.html for all url Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

.html for all url Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
hfa_settings_callback (admin\class-hfa-setting.php:93)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

.html for all url Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuadmin\class-hfa-setting.php:31
actionadmin_enqueue_scriptsadmin\class-hfa-setting.php:32
actioninitclass-html-for-all.php:36
filteruser_trailingslashitclass-html-for-all.php:39
filterredirect_canonicalclass-html-for-all.php:44
filterrewrite_rules_arrayclass-html-for-all.php:45
filterpost_type_linkclass-html-for-all.php:46
Maintenance & Trust

.html for all url Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedAug 3, 2017
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Alternatives

.html for all url Alternatives

Developer Profile

.html for all url Developer Profile

1naveengiri

2 plugins · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect .html for all url

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/html-for-all-url/admin/style.css

HTML / DOM Fingerprints

CSS Classes
hfa_setting_containrehfa_pluing_informationhfa_infoupdatehfa_setting_formpost_types_lists
Data Attributes
name="hfa_post_types[ ]"
FAQ

Frequently Asked Questions about .html for all url