
Custom HTML/PHP Post Templates Security & Risk Analysis
wordpress.org/plugins/html-php-pages-and-postsUse your HTML or PHP files for any page or post.
Is Custom HTML/PHP Post Templates Safe to Use in 2026?
Generally Safe
Score 85/100Custom HTML/PHP Post Templates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "html-php-pages-and-posts" v2.0.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive indicator. Furthermore, all SQL queries utilize prepared statements, which is a crucial security practice.
The primary area of concern lies in the output escaping. With only 6% of 33 outputs being properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied or dynamically generated content displayed on the frontend may not be adequately sanitized, potentially allowing attackers to inject malicious scripts.
The plugin's vulnerability history is clean, with no known CVEs. This, combined with the limited attack surface and apparent adherence to basic security practices like nonce and capability checks, suggests that the developers have a foundational understanding of security. However, the poor output escaping practices present a clear and present risk that needs immediate attention.
Key Concerns
- Poor output escaping practices
Custom HTML/PHP Post Templates Security Vulnerabilities
Custom HTML/PHP Post Templates Release Timeline
Custom HTML/PHP Post Templates Code Analysis
Output Escaping
Custom HTML/PHP Post Templates Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Custom HTML/PHP Post Templates Maintenance & Trust
Maintenance Signals
Community Trust
Custom HTML/PHP Post Templates Alternatives
Code Widget
code-widget
Code widget help to add Short Code, PHP Code, HTML, and Simple Text in widget.
Append extensions on Pages
append-extensions-on-pages
This plugin helps to appends .html or .asp or .htm etc on the wordpress pages when used with permalink.
WP Page Templates
custom-page-templates-by-vegacorp
Create full width pages, add left or right sidebars, add above or below content sidebars.
Hide Header on Posts for Landing Pages
hide-header-on-posts-for-a-landing-page
Hide header on single post pages.
2MB Autocode
2mb-autocode
This plugin allows you to place predetermined text/html/php at the top or bottom of posts.
Custom HTML/PHP Post Templates Developer Profile
1 plugin · 70 total installs
How We Detect Custom HTML/PHP Post Templates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/html-php-pages-and-posts/admin/js/custom-pages-and-posts.js/wp-content/plugins/html-php-pages-and-posts/admin/css/custom-pages-and-posts.css/wp-content/plugins/html-php-pages-and-posts/admin/js/custom-pages-and-posts.jsHTML / DOM Fingerprints
onclick="select_template(event, onclick="delete_template(event, select_templatedelete_template[html_php_page_post]