MarkuClean – AI Markup Cleaner Security & Risk Analysis

wordpress.org/plugins/markuclean-markup-cleaner

MarkuClean Markup Cleaner cleans and normalizes post content in supported WordPress editing contexts.

0 active installs v1.0.2 PHP 8.0+ WP 5.8+ Updated Apr 9, 2026
aiclassic-editorcontent-cleanupgutenbergmarkup
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is MarkuClean – AI Markup Cleaner Safe to Use in 2026?

Generally Safe

Score 100/100

MarkuClean – AI Markup Cleaner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The markuclean-markup-cleaner plugin, version 1.0.0, exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, external HTTP requests, and critical or high severity taint flows are all positive indicators. The use of prepared statements for all SQL queries and the presence of capability checks further bolster its security. However, there are a few areas for improvement. Notably, the complete lack of nonce checks across all identified entry points (AJAX and REST API) presents a significant concern. While no unpatched CVEs are recorded, indicating a history of security diligence or a lack of past discoveries, the potential for vulnerability exploitation due to missing nonces remains. The moderate output escaping rate, while not critically low, suggests that some outputs might be susceptible to cross-site scripting (XSS) if not properly handled by the theme or other plugins. In conclusion, the plugin demonstrates good foundational security practices but has a clear weakness in authentication/authorization mechanisms for its entry points. Addressing the missing nonce checks and improving output escaping should be prioritized to further enhance its security.

Key Concerns

  • Missing nonce checks on all entry points
  • Moderate output escaping (73%)
Vulnerabilities
None known

MarkuClean – AI Markup Cleaner Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MarkuClean – AI Markup Cleaner Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

MarkuClean – AI Markup Cleaner Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
17
45 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

73% escaped62 total outputs
Attack Surface

MarkuClean – AI Markup Cleaner Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

POST/wp-json/aicc/v1/sanitizeincludes\Editor\Integration.php:81
WordPress Hooks 17
actionadmin_menuincludes\Admin\Settings.php:19
actionadmin_initincludes\Admin\Settings.php:20
actionadmin_enqueue_scriptsincludes\Admin\Settings.php:21
actionenqueue_block_editor_assetsincludes\Editor\Integration.php:19
filterthe_postsincludes\Frontend\Display.php:17
filterthe_titleincludes\Frontend\Display.php:20
filterthe_contentincludes\Frontend\Display.php:21
filterthe_excerptincludes\Frontend\Display.php:22
actionrest_api_initincludes\Plugin.php:19
filterwp_insert_post_dataincludes\Plugin.php:31
filtersanitize_post_meta__elementor_dataincludes\Plugin.php:32
filterwp_insert_post_dataincludes\Plugin.php:40
filtercontent_save_preincludes\Plugin.php:43
filtertitle_save_preincludes\Plugin.php:44
filterexcerpt_save_preincludes\Plugin.php:45
actioninitmarkuclean-markup-cleaner.php:64
actionplugins_loadedmarkuclean-markup-cleaner.php:68
Maintenance & Trust

MarkuClean – AI Markup Cleaner Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 9, 2026
PHP min version8.0
Downloads334

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MarkuClean – AI Markup Cleaner Developer Profile

Ivijan-Stefan Stipic

7 plugins · 95K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
285 days
View full developer profile
Detection Fingerprints

How We Detect MarkuClean – AI Markup Cleaner

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/markuclean-markup-cleaner/assets/css/admin.css/wp-content/plugins/markuclean-markup-cleaner/assets/js/admin.js/wp-content/plugins/markuclean-markup-cleaner/assets/js/editor.js
Version Parameters
markuclean-markup-cleaner/assets/css/admin.css?ver=markuclean-markup-cleaner/assets/js/admin.js?ver=markuclean-markup-cleaner/assets/js/editor.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-aicc-sidebar-preview
JS Globals
window.AICC_Admin
FAQ

Frequently Asked Questions about MarkuClean – AI Markup Cleaner