
Mammoth .docx converter Security & Risk Analysis
wordpress.org/plugins/mammoth-docx-converterMammoth converts semantically marked up .docx documents to simple and clean HTML, allowing pasting from Word and Google Docs without the usual mess.
Is Mammoth .docx converter Safe to Use in 2026?
Generally Safe
Score 100/100Mammoth .docx converter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mammoth-docx-converter plugin v1.22.0 exhibits a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, external HTTP requests, and its use of prepared statements for all SQL queries are commendable practices. Furthermore, the complete lack of any recorded CVEs or known vulnerabilities is a significant positive indicator of its historical security. The plugin also presents a remarkably small attack surface with zero identified entry points in AJAX handlers, REST API routes, shortcodes, or cron events.
However, a critical concern arises from the total lack of output escaping, with 0% of the five identified output operations being properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or processed data could be injected directly into the output without sanitization, potentially allowing attackers to execute malicious scripts in a user's browser. Additionally, the absence of nonce and capability checks on any entry points (though there are none identified) means that if any were to be introduced or discovered later, they would be inherently unprotected. This combination of a clean history and zero-day potential due to unescaped output requires careful consideration.
In conclusion, while the plugin has a strong track record and a minimal attack surface, the critical deficiency in output escaping is a glaring weakness that needs immediate attention. The potential for XSS vulnerabilities, despite the lack of known historical issues, makes this plugin a moderate risk until the output escaping is addressed. The complete absence of taint analysis results is also noted, though this might be due to the limited attack surface or the specific analysis tools used.
Key Concerns
- Unescaped output
- No nonce checks on entry points
- No capability checks on entry points
Mammoth .docx converter Security Vulnerabilities
Mammoth .docx converter Code Analysis
Output Escaping
Mammoth .docx converter Attack Surface
WordPress Hooks 3
Maintenance & Trust
Mammoth .docx converter Maintenance & Trust
Maintenance Signals
Community Trust
Mammoth .docx converter Alternatives
Docxpresso
docxpresso
"Copy and Paste" from MS Word, Excel, Libre Office or Open Office.
Word to html
word-to-html
Display some html from one or more word files from your local webserver or an external webserver.
Export WordPress Pages to Static HTML & PDF — Static Site Export
export-wp-page-to-static-html
Export WordPress pages, posts, and custom post types to clean static HTML or PDF files in one click. Create fast, secure static versions of your WordP …
Video gallery and Player
html5-videogallery-plus-player
Easy to add and display your HTML5, YouTube, Vimeo vedio gallery with Magnific Popup to your website. Also work with Gutenberg shortcode block.
Seraphinite Post .DOCX Source
seraphinite-post-docx-source
Save your time by automatically converting from .DOCX to content with all WordPress post attributes.
Mammoth .docx converter Developer Profile
1 plugin · 30K total installs
How We Detect Mammoth .docx converter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mammoth-docx-converter/mammoth.css/wp-content/plugins/mammoth-docx-converter/mammoth-editor.js/wp-content/plugins/mammoth-docx-converter/tabs.jsmammoth-docx-converter/mammoth.css?ver=1.3.0mammoth-docx-converter/mammoth-editor.js?v=1.22.0mammoth-docx-converter/tabs.js?v=1.22.0HTML / DOM Fingerprints
mammoth-docx-uploaderstatus-emptymammoth-docx-loadingmammoth-docx-insertingmammoth-docx-errormammoth-docx-error-messagemammoth-docx-previewmammoth-tabs+4 moreid="mammoth-docx-uploader"id="mammoth-docx-upload"id="mammoth-docx-loading"id="mammoth-docx-inserting"class="mammoth-docx-error"id="mammoth-docx-error-message"+10 more