
HTML Import 2 Security & Risk Analysis
wordpress.org/plugins/import-html-pagesImports well-formed HTML files into WordPress pages.
Is HTML Import 2 Safe to Use in 2026?
Generally Safe
Score 85/100HTML Import 2 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "import-html-pages" v2.6 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a history of no recorded vulnerabilities, coupled with 100% of SQL queries using prepared statements, are positive indicators. Furthermore, the limited attack surface with zero unprotected entry points is commendable. However, there are areas of concern that warrant attention. The presence of two instances of the `create_function` dangerous function, while not directly exploited in the provided analysis, represents a known security risk in PHP and should ideally be refactored. Additionally, a 71% rate of proper output escaping, while not critically low, suggests that a portion of the plugin's output may be vulnerable to cross-site scripting (XSS) attacks if not properly handled by WordPress core or other security measures. The limited taint analysis results are encouraging, indicating no critical or high severity unsanitized flows were detected.
Key Concerns
- Use of dangerous function create_function
- Output escaping only 71% proper
HTML Import 2 Security Vulnerabilities
HTML Import 2 Code Analysis
Dangerous Functions Found
Output Escaping
HTML Import 2 Attack Surface
WordPress Hooks 4
Maintenance & Trust
HTML Import 2 Maintenance & Trust
Maintenance Signals
Community Trust
HTML Import 2 Alternatives
Socius Marketing Page Taxonomy
socius-marketing-page-taxonomy
Adds 2 custom taxonomies (categories & areas served) to Pages for easy, dynamic archive listing.
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
TagPages
tagpages
Adds post-tags functionality for pages.
CIO Custom Fields Importer
custom-fields-csv-xml-importer
Simple, easy, fast and flexible, this add-on to WP All Import processes large data sets from any XML or CSV files to any contents.
Simple Taxonomy Refreshed
simple-taxonomy-refreshed
This plugin provides a no-code facility to manage your taxonomies - either by defining your own or by adding additional function to existing ones.
HTML Import 2 Developer Profile
16 plugins · 17K total installs
How We Detect HTML Import 2
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/import-html-pages/html-import-styles.css/wp-content/plugins/import-html-pages/js/tabs.js/wp-content/plugins/import-html-pages/js/tabs.jsHTML / DOM Fingerprints
ui-tabsui-tabs-navnav-tab-wrappernav-tabdata-region