
LH HTML Cleaner Security & Risk Analysis
wordpress.org/plugins/lh-html-cleanerRemoves blacklisted html tags and attributes.
Is LH HTML Cleaner Safe to Use in 2026?
Generally Safe
Score 100/100LH HTML Cleaner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The lh-html-cleaner plugin v1.33 exhibits a strong security posture in several key areas, notably the absence of known vulnerabilities and a complete lack of SQL queries that are not prepared. The plugin also demonstrates good practices by implementing capability checks and having no external HTTP requests or file operations, which are common vectors for exploits. Furthermore, the static analysis reveals no critical or high severity taint flows, suggesting that data handling within the plugin is generally secure.
However, a significant concern arises from the low percentage (36%) of properly escaped outputs. This indicates a potential for cross-site scripting (XSS) vulnerabilities, as user-supplied data or internal data that is not properly sanitized before being displayed to the user could be manipulated. While there are no reported vulnerabilities currently, the presence of unescaped output represents a latent risk that could be exploited if a suitable attack vector is discovered. The plugin also has a complete lack of nonce checks and AJAX handlers, which while contributing to a smaller attack surface, also means there's no specific mechanism to prevent replay attacks or unauthorized actions via these channels if they were to be introduced in the future.
In conclusion, the plugin benefits from a clean vulnerability history and secure database interactions. The primary weakness lies in its output escaping practices, which presents a tangible risk of XSS. The absence of any recorded vulnerabilities in the past is a positive indicator, but the code analysis suggests that the developers should prioritize improving output escaping to mitigate the identified XSS risk.
Key Concerns
- Low percentage of properly escaped output
LH HTML Cleaner Security Vulnerabilities
LH HTML Cleaner Code Analysis
Output Escaping
LH HTML Cleaner Attack Surface
WordPress Hooks 4
Maintenance & Trust
LH HTML Cleaner Maintenance & Trust
Maintenance Signals
Community Trust
LH HTML Cleaner Alternatives
Style Stripper
style-stripper
Removes all inline style tags from the content of posts/pages/custom post types.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
WP Comment Cleaner – Delete All Comments, Disable Comments, Bulk Delete & Remove Comments
delete-all-comments-of-website
Delete comments, disable comments, and remove comments in one click. Bulk delete spam and all comments to optimize your WordPress database easily.
Remove Yoast SEO Comments
remove-yoast-seo-comments
Removes the Yoast SEO advertisement HTML comments from your front-end source code.
Disable Comments & Delete All Comments
comments-plus
Disable comments globally on all posts or certain post types. Delete all comments at once, by post type or comment status. Manage links in comments.
LH HTML Cleaner Developer Profile
77 plugins · 15K total installs
How We Detect LH HTML Cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.