
HTML to Post Security & Risk Analysis
wordpress.org/plugins/html-to-postThe HTML, CSS and JS file you choose will be inserted Your post or page.
Is HTML to Post Safe to Use in 2026?
Generally Safe
Score 100/100HTML to Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "html-to-post" v1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices by exclusively using prepared statements for SQL queries and has no recorded vulnerability history, suggesting a development team that prioritizes security or a lack of prior high-impact issues. The absence of external HTTP requests and bundled libraries also reduces potential attack vectors. However, significant concerns arise from the code analysis. The fact that 0% of its 38 output operations are properly escaped is a critical flaw, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Furthermore, while the taint analysis shows no critical or high severity flows, the presence of 2 flows with unsanitized paths, even if low severity, warrants attention, especially in conjunction with the unescaped output.
Key Concerns
- 0% of output operations are properly escaped
- 2 taint flows with unsanitized paths
- 0 Nonce checks on entry points
HTML to Post Security Vulnerabilities
HTML to Post Code Analysis
Output Escaping
Data Flow Analysis
HTML to Post Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
HTML to Post Maintenance & Trust
Maintenance Signals
Community Trust
HTML to Post Alternatives
Raw HTML
raw-html
Lets you use raw HTML or any other code in your posts. You can also disable smart quotes and other automatic formatting on a per-post basis.
WP Minify Fix
wp-minify-fix
[Fixed] This plugin uses the Minify engine to combine and compress JS and CSS files to improve page load time.
Insert Code by Angie Makes
wpc-insert-code
Easily insert HTML, Javascript, CSS, into the head and footer areas of your site.
Specific CSS/JS for Posts and Pages
specific-cssjs-for-posts-and-pages
With Specific CSS/JS for Posts and Pages you can add CSS or JavaScript files to a specific page or post.
Insert JS or CSS in post via Custom Field
insert-js-or-css-in-post-via-custom-field
This plugin will insert urls of JavaScript or CSS stylesheet files added into a particular posts or page via Custom Fields.
HTML to Post Developer Profile
5 plugins · 140 total installs
How We Detect HTML to Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/html-to-post/style.csshtml-to-post/style.css?ver=HTML / DOM Fingerprints
unsetdata-post_idsjHtmlToPost[html2post /]