
MarkuClean – AI Markup Cleaner Security & Risk Analysis
wordpress.org/plugins/markuclean-markup-cleanerMarkuClean Markup Cleaner cleans and normalizes post content in supported WordPress editing contexts.
Is MarkuClean – AI Markup Cleaner Safe to Use in 2026?
Generally Safe
Score 100/100MarkuClean – AI Markup Cleaner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The markuclean-markup-cleaner plugin, version 1.0.0, exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, external HTTP requests, and critical or high severity taint flows are all positive indicators. The use of prepared statements for all SQL queries and the presence of capability checks further bolster its security. However, there are a few areas for improvement. Notably, the complete lack of nonce checks across all identified entry points (AJAX and REST API) presents a significant concern. While no unpatched CVEs are recorded, indicating a history of security diligence or a lack of past discoveries, the potential for vulnerability exploitation due to missing nonces remains. The moderate output escaping rate, while not critically low, suggests that some outputs might be susceptible to cross-site scripting (XSS) if not properly handled by the theme or other plugins. In conclusion, the plugin demonstrates good foundational security practices but has a clear weakness in authentication/authorization mechanisms for its entry points. Addressing the missing nonce checks and improving output escaping should be prioritized to further enhance its security.
Key Concerns
- Missing nonce checks on all entry points
- Moderate output escaping (73%)
MarkuClean – AI Markup Cleaner Security Vulnerabilities
MarkuClean – AI Markup Cleaner Release Timeline
MarkuClean – AI Markup Cleaner Code Analysis
SQL Query Safety
Output Escaping
MarkuClean – AI Markup Cleaner Attack Surface
REST API Routes 1
WordPress Hooks 17
Maintenance & Trust
MarkuClean – AI Markup Cleaner Maintenance & Trust
Maintenance Signals
Community Trust
MarkuClean – AI Markup Cleaner Alternatives
News in 100 Words
news-in-100-words
Automatically generates AI-powered 100-word news summaries for WordPress posts with editor support, front-end display, and Thunderbolt carousel.
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Disable Gutenberg
disable-gutenberg
Disable Gutenberg Block Editor and restore the Classic Editor and original Edit Post screen (TinyMCE, meta boxes, etc.).
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
essential-blocks
Gutenberg block editor with AI. 70+ Gutenberg blocks, patterns, WooCommerce blocks, post grid, gallery, menu with Gutenberg block library.
MarkuClean – AI Markup Cleaner Developer Profile
7 plugins · 95K total installs
How We Detect MarkuClean – AI Markup Cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/markuclean-markup-cleaner/assets/css/admin.css/wp-content/plugins/markuclean-markup-cleaner/assets/js/admin.js/wp-content/plugins/markuclean-markup-cleaner/assets/js/editor.jsmarkuclean-markup-cleaner/assets/css/admin.css?ver=markuclean-markup-cleaner/assets/js/admin.js?ver=markuclean-markup-cleaner/assets/js/editor.js?ver=HTML / DOM Fingerprints
data-aicc-sidebar-previewwindow.AICC_Admin