
HTTPS Mixed Content Detector Security & Risk Analysis
wordpress.org/plugins/https-mixed-content-detectorDetects and logs content that will cause mixed content warnings.
Is HTTPS Mixed Content Detector Safe to Use in 2026?
Generally Safe
Score 85/100HTTPS Mixed Content Detector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The https-mixed-content-detector plugin v1.2.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, critical or high severity taint flows, and a complete lack of SQL injection vulnerabilities due to the exclusive use of prepared statements are significant strengths. Furthermore, the plugin demonstrates good practices by incorporating nonce and capability checks, and a high percentage of properly escaped output, indicating an awareness of common web application security risks. The limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, further reduces the potential for exploitation.
Despite the positive indicators, there are minor areas for consideration. The presence of file operations and external HTTP requests, while not inherently problematic, could present potential risks if not handled with extreme care and robust validation, especially in combination with less than perfectly escaped output. The 13% of output that is not properly escaped, though seemingly small, could still be a vector for cross-site scripting (XSS) vulnerabilities if the unescaped data originates from an untrusted source or is rendered in a sensitive context. The lack of any taint analysis flows being analyzed is also a point of interest, suggesting either a very simple code structure or that such analysis was not performed comprehensively.
In conclusion, https-mixed-content-detector v1.2.0 appears to be a securely developed plugin with a history free of significant vulnerabilities. The development team has implemented many best practices. The primary areas for vigilance would be ensuring the secure handling of file operations and external requests, and diligently addressing the remaining unescaped output to achieve a fully robust security profile.
Key Concerns
- Unescaped output exists
- File operations present
- External HTTP requests present
HTTPS Mixed Content Detector Security Vulnerabilities
HTTPS Mixed Content Detector Code Analysis
Output Escaping
HTTPS Mixed Content Detector Attack Surface
WordPress Hooks 6
Maintenance & Trust
HTTPS Mixed Content Detector Maintenance & Trust
Maintenance Signals
Community Trust
HTTPS Mixed Content Detector Alternatives
Simple HTTPS
simple-https
Correct your SSL/HTTPS issue within few clicks and enable HTTP Strict Transport Security for your website.
HTTPS Domain Alias
https-domain-alias
Enable your site to have a different domains for HTTP and HTTPS.
Easy HTTPS Redirection (SSL)
https-redirection
The plugin allows an automatic redirection to the "HTTPS" version/URL of the site. Make your site SSL compatible easily.
SSL Insecure Content Fixer
ssl-insecure-content-fixer
Clean up WordPress website HTTPS insecure content
WP Force SSL & HTTPS SSL Redirect
wp-force-ssl
Enable SSL & HTTPS redirect with 1 click! Add SSL certificate & WP Force SSL to redirect site from HTTP to HTTPS & fix SSL errors.
HTTPS Mixed Content Detector Developer Profile
6 plugins · 1K total installs
How We Detect HTTPS Mixed Content Detector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/https-mixed-content-detector/assets/js/mcd-beacon.js/wp-content/plugins/https-mixed-content-detector/assets/css/mcd-styles.cssHTTPS Mixed Content Detector/wp-content/plugins/https-mixed-content-detector/assets/js/mcd-beacon.jshttps-mixed-content-detector/assets/js/mcd-beacon.js?ver=https-mixed-content-detector/assets/css/mcd-styles.css?ver=HTML / DOM Fingerprints
mcd-dashboard-widgetMCD_BEACON_CONFIG