
HTML to Post Security & Risk Analysis
wordpress.org/plugins/html-to-postThe HTML, CSS and JS file you choose will be inserted Your post or page.
Is HTML to Post Safe to Use in 2026?
Generally Safe
Score 85/100HTML to Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "html-to-post" v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices by exclusively using prepared statements for SQL queries and has no recorded vulnerability history, suggesting a development team that prioritizes security or a lack of prior high-impact issues. The absence of external HTTP requests and bundled libraries also reduces potential attack vectors. However, significant concerns arise from the code analysis. The fact that 0% of its 38 output operations are properly escaped is a critical flaw, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Furthermore, while the taint analysis shows no critical or high severity flows, the presence of 2 flows with unsanitized paths, even if low severity, warrants attention, especially in conjunction with the unescaped output.
Key Concerns
- 0% of output operations are properly escaped
- 2 taint flows with unsanitized paths
- 0 Nonce checks on entry points
HTML to Post Security Vulnerabilities
HTML to Post Release Timeline
HTML to Post Code Analysis
Output Escaping
Data Flow Analysis
HTML to Post Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
HTML to Post Maintenance & Trust
Maintenance Signals
Community Trust
HTML to Post Alternatives
Raw HTML
raw-html
Lets you use raw HTML or any other code in your posts. You can also disable smart quotes and other automatic formatting on a per-post basis.
WP Minify Fix
wp-minify-fix
[Fixed] This plugin uses the Minify engine to combine and compress JS and CSS files to improve page load time.
Insert Code by Angie Makes
wpc-insert-code
Easily insert HTML, Javascript, CSS, into the head and footer areas of your site.
Specific CSS/JS for Posts and Pages
specific-cssjs-for-posts-and-pages
With Specific CSS/JS for Posts and Pages you can add CSS or JavaScript files to a specific page or post.
Insert JS or CSS in post via Custom Field
insert-js-or-css-in-post-via-custom-field
This plugin will insert urls of JavaScript or CSS stylesheet files added into a particular posts or page via Custom Fields.
HTML to Post Developer Profile
6 plugins · 130 total installs
How We Detect HTML to Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/html-to-post/style.csshtml-to-post/style.css?ver=HTML / DOM Fingerprints
unsetdata-post_idsjHtmlToPost[html2post /]