
HTML Landing Page Security & Risk Analysis
wordpress.org/plugins/html-landing-pageAllows you to upload customized HTML files to display as a landing page. Ideal for internet marketers promoting multiple products from the same site.
Is HTML Landing Page Safe to Use in 2026?
Generally Safe
Score 85/100HTML Landing Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "html-landing-page" plugin v1.0 exhibits a mixed security posture. On one hand, it has a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are correctly implemented using prepared statements, indicating good database interaction practices. However, significant concerns arise from the code signals and taint analysis. The presence of the `exec` function, a dangerous function that can execute arbitrary commands, is a major red flag. Compounding this, 100% of output is not properly escaped, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals a critical severity flow with an unsanitized path, strongly suggesting a command injection or path traversal vulnerability, especially when combined with the `exec` function.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This could indicate a well-developed plugin or simply a lack of historical scrutiny. However, the current code analysis findings present immediate and critical risks that overshadow the clean history. The absence of nonces and capability checks on any potential, albeit currently unexposed, entry points is also a weakness that could be exploited if the attack surface were to expand in future versions. In conclusion, while the plugin has strengths in its limited attack surface and secure SQL usage, the critical findings from taint analysis and code signals (especially `exec` and unescaped output) present a substantial security risk that requires immediate attention.
Key Concerns
- Critical taint flow with unsanitized path
- Dangerous function 'exec' used
- 100% of outputs are not properly escaped
- No nonce checks present
- No capability checks present
HTML Landing Page Security Vulnerabilities
HTML Landing Page Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
HTML Landing Page Attack Surface
WordPress Hooks 3
Maintenance & Trust
HTML Landing Page Maintenance & Trust
Maintenance Signals
Community Trust
HTML Landing Page Alternatives
CJ Network Integration
cj-affiliate-network-integration
Seamlessly integrate with CJ Network, the world’s leading performance-based marketing platform.
Tracking Code for cj.com (on WooCommerce checkout)
code-for-cj-affiliate-network
Installs the tracking code for cj.com
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode
coming-soon
Easy Drag & Drop Page Builder. A complete solution to create a WordPress Website, Custom Themes, Landing Pages, Coming Soon & Maintenance Mode Pages.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
HTML Landing Page Developer Profile
1 plugin · 10 total installs
How We Detect HTML Landing Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
lp-admin-wrapdata-lp-selected-pagedata-lp-redir-302data-lp-rewrite-jsdata-lp-rewrite-cssdata-lp-rewrite-linksdata-lp-rewrite-img+2 more