
HTML Tag and Class Replace Security & Risk Analysis
wordpress.org/plugins/html-tag-and-class-replaceAllows you to Replace any HTML Tag and Class of your WordPress WebSite.
Is HTML Tag and Class Replace Safe to Use in 2026?
Generally Safe
Score 100/100HTML Tag and Class Replace has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "html-tag-and-class-replace" v1.1.1 exhibits a generally good security posture based on the provided static analysis. The plugin demonstrates strong adherence to secure coding practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and performing nonce checks on its single AJAX entry point. The complete absence of file operations, external HTTP requests, and shortcodes/cron events further minimizes the potential attack surface. The lack of any recorded vulnerabilities in its history is also a positive indicator.
However, a key area for concern is the absence of capability checks for its AJAX handler. While a nonce check is present, allowing any authenticated user to potentially trigger this handler without proper authorization checks could lead to unintended actions or privilege escalation if the handler's functionality is sensitive. Additionally, the 30% of output that is not properly escaped, while not flagged as critical in taint analysis, represents a potential cross-site scripting (XSS) risk if the unescaped output is derived from user-supplied data. The lack of taint analysis results is also notable; while it might indicate no flows were found, a more comprehensive analysis could provide greater confidence.
Key Concerns
- Missing capability checks on AJAX handler
- Unescaped output present
HTML Tag and Class Replace Security Vulnerabilities
HTML Tag and Class Replace Code Analysis
Output Escaping
HTML Tag and Class Replace Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
HTML Tag and Class Replace Maintenance & Trust
Maintenance Signals
Community Trust
HTML Tag and Class Replace Alternatives
AddFunc Head & Footer Code
addfunc-head-footer-code
Easily add code to your head, footer and/or immediately after the opening body tag, site-wide and/or on any individual page/post.
Embed Code – Headers & Footers by DesignBombs
embed-code
The easiest way to embed code in the head or footer of your site, globally or on a per-page/post basis.
Add Custom Codes – Insert Header, Footer, Custom PHP Snippets, CSS, Javascript
add-custom-codes
Add custom codes to your wordpress site. A completely free plugin to add Custom PHP functions, HTML, CSS, Javascript, any other codes to your website.
CSS Ready Classes for Gravity Forms
css-ready-classes-gravity-forms
Conveniently select Gravity Form CSS Ready Classes from your form fields Appearance tab.
Simple CSS for widgets
simple-css-for-widgets
This plugin lets you specify CSS class(s) for widgets to apply your own CSS definitions to specific widgets.
HTML Tag and Class Replace Developer Profile
4 plugins · 11K total installs
How We Detect HTML Tag and Class Replace
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/html-tag-and-class-replace/assets/admin/css/style.css/wp-content/plugins/html-tag-and-class-replace/assets/admin/js/admin.js/wp-content/plugins/html-tag-and-class-replace/assets/app/js/replace.js/wp-content/plugins/html-tag-and-class-replace/assets/admin/js/admin.js/wp-content/plugins/html-tag-and-class-replace/assets/app/js/replace.jshtml-tag-and-class-replace/assets/admin/css/style.css?ver=html-tag-and-class-replace/assets/admin/js/admin.js?ver=html-tag-and-class-replace/assets/app/js/replace.js?ver=HTML / DOM Fingerprints
htmlReplaceAjaxhtc_data