
HTML Purified Security & Risk Analysis
wordpress.org/plugins/html-purifiedHTML Purified replaces the default comments filters with the more secure HTML Purifier.
Is HTML Purified Safe to Use in 2026?
Generally Safe
Score 85/100HTML Purified has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'html-purified' v0.7 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any attack surface points, such as AJAX handlers, REST API routes, shortcodes, or cron events, is a significant strength, indicating the plugin is not directly exposed to common web vulnerabilities. Furthermore, the complete reliance on prepared statements for all SQL queries and the lack of any recorded vulnerabilities or CVEs suggest a well-developed and secure codebase. This indicates diligent attention to secure coding practices in these critical areas.
However, the analysis does reveal some areas for improvement. The output escaping is only properly implemented for 50% of the identified outputs, which presents a potential risk of Cross-Site Scripting (XSS) vulnerabilities if untrusted data is displayed without adequate sanitization. While there are no reported vulnerabilities currently, this oversight in output handling warrants attention. The presence of file operations without further context is also a minor concern, as this could potentially be an attack vector if not handled securely, though the lack of taint flow analysis makes it impossible to confirm.
In conclusion, 'html-purified' v0.7 is commendably secure in its handling of direct web entry points and database interactions, and its history is clean. The primary area of concern is the inconsistent output escaping, which could lead to XSS vulnerabilities. Addressing this would further solidify its security.
Key Concerns
- Output escaping only 50% properly
HTML Purified Security Vulnerabilities
HTML Purified Code Analysis
Output Escaping
HTML Purified Attack Surface
WordPress Hooks 20
Maintenance & Trust
HTML Purified Maintenance & Trust
Maintenance Signals
Community Trust
HTML Purified Alternatives
Comment Form CSRF Protection
comment-form-csrf-protection
Prevent Cross-Site Request Forgery attacks on your comments form.
Spam Comment Remover
spam-comment-remover
Automatically remove spam comments without Akismet. Universal spam detection that blocks junk, hidden links, fake names, gibberish, and automated subm …
GhostTrap
ghosttrap
Advanced 5-layer invisible spam protection for comments. No captcha, no user friction - professional spam blocking.
Back List
back-list
Adds Whitelist and Blacklist options for Trackbacks and Pingbacks
Identityplus
identity-plus
Identityplus is a novel security solution based on PKI (Public Key Infrastructure) called a network of trust. It features an all-in-one 2 (ocasionally …
HTML Purified Developer Profile
14 plugins · 2.1M total installs
How We Detect HTML Purified
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/html-purified/css/admin.css/wp-content/plugins/html-purified/js/admin.jsHTML / DOM Fingerprints
hp-admin-boxhp-admin-fieldhp-admin-field-label<!-- HTML Purifier Settings -->data-fordata-inputdata-outputhtml_purified_options