
Load HTML Files Security & Risk Analysis
wordpress.org/plugins/load-html-filesEffortlessly load HTML files from a folder into posts with our WordPress plugin. Simplify your workflow and enhance your site's presentation today.
Is Load HTML Files Safe to Use in 2026?
Generally Safe
Score 92/100Load HTML Files has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'load-html-files' v1.1.1 plugin demonstrates a generally good security posture with several positive indicators. Notably, all identified SQL queries utilize prepared statements, and all output is properly escaped, mitigating common risks associated with data injection and cross-site scripting. The absence of external HTTP requests and the limited number of file operations further reduce the potential for certain types of attacks. However, the presence of a dangerous 'assert' function, while not directly exploitable without a specific context or flow, represents a potential concern that could be leveraged in conjunction with other weaknesses if they were to exist. Furthermore, the complete absence of nonce checks and capability checks across all entry points, including a registered cron event, is a significant oversight. This means that any functionality triggered by the cron event could be invoked by unauthenticated users or users with insufficient privileges, potentially leading to unintended actions or even privilege escalation if the cron event's task has sensitive implications. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong positive. This suggests that in the past, developers have maintained a reasonable level of security. Overall, the plugin has strengths in its handling of SQL and output, but the lack of authorization checks and the presence of the 'assert' function warrant attention.
Key Concerns
- Dangerous function 'assert' present
- 0 Nonce checks on entry points
- 0 Capability checks on entry points
Load HTML Files Security Vulnerabilities
Load HTML Files Code Analysis
Dangerous Functions Found
Output Escaping
Load HTML Files Attack Surface
WordPress Hooks 11
Scheduled Events 1
Maintenance & Trust
Load HTML Files Maintenance & Trust
Maintenance Signals
Community Trust
Load HTML Files Alternatives
No alternatives data available yet.
Load HTML Files Developer Profile
13 plugins · 79K total installs
How We Detect Load HTML Files
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/load-html-files/assets/css/load-html-files.css/wp-content/plugins/load-html-files/assets/js/load-html-files.js/wp-content/plugins/load-html-files/assets/js/load-html-files.jsload-html-files/assets/css/load-html-files.css?ver=load-html-files/assets/js/load-html-files.js?ver=HTML / DOM Fingerprints
fs-settings-meta-box-wrapif-js-closedcloseddata-hook-suffixpostboxes