
MTM HTML to Markdown Security & Risk Analysis
wordpress.org/plugins/mtm-html-to-markdownConverts any WordPress page or post to Markdown at a .md.txt URL with caching and YAML headers.
Is MTM HTML to Markdown Safe to Use in 2026?
Generally Safe
Score 100/100MTM HTML to Markdown has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mtm-html-to-markdown plugin version 1.0.0 exhibits a generally good security posture based on the provided static analysis. The complete absence of entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the lack of identified critical or high severity taint flows and no recorded vulnerability history are positive indicators. The presence of a nonce check and a reasonable output escaping rate (72%) also suggest some attention to security best practices.
However, there are a couple of areas that warrant caution. The plugin performs two SQL queries, and neither utilizes prepared statements, presenting a potential risk for SQL injection vulnerabilities if user-supplied data is directly incorporated into these queries. While there are no explicitly dangerous functions called or file operations performed, the single external HTTP request could be a vector for various attacks if not handled securely. The absence of capability checks for any potential (though currently non-existent) entry points is also a weakness, though less impactful given the current attack surface.
In conclusion, the plugin has a strong foundation with a minimal attack surface and no known historical vulnerabilities. The primary concern lies with the unescaped SQL queries. If the plugin's functionality evolves to include user input in these queries without implementing proper sanitization or prepared statements, it could become a significant security risk. The external HTTP request also needs careful review to ensure it's implemented securely.
Key Concerns
- SQL queries without prepared statements
- External HTTP request without apparent checks
- No capability checks on potential entry points
MTM HTML to Markdown Security Vulnerabilities
MTM HTML to Markdown Code Analysis
SQL Query Safety
Output Escaping
MTM HTML to Markdown Attack Surface
WordPress Hooks 7
Maintenance & Trust
MTM HTML to Markdown Maintenance & Trust
Maintenance Signals
Community Trust
MTM HTML to Markdown Alternatives
Export WordPress Pages to Static HTML & PDF — Static Site Export
export-wp-page-to-static-html
Export WordPress pages, posts, and custom post types to clean static HTML or PDF files in one click. Create fast, secure static versions of your WordP …
Ultimate Markdown – Markdown Editor, Importer, & Exporter
ultimate-markdown
Generate block-based articles from a Markdown file, bulk import and export Markdown documents, create Markdown documents from an editor, and more.
Simple Export to Markdown
simple-export-md
Adds a Gutenberg editor panel to export any post or page content to Markdown format (.md file or clipboard).
WP Gatsby Markdown Exporter
wp-gatsby-markdown-exporter
Export WordPress content to Markdown for GatsbyJS.
Blog To HTML
blog-to-html
Export all posts in your blog to a HTML file for ebook creation.
MTM HTML to Markdown Developer Profile
2 plugins · 10 total installs
How We Detect MTM HTML to Markdown
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mtm-html-to-markdown/assets/js/admin-force-update.js/wp-content/plugins/mtm-html-to-markdown/assets/js/admin-force-update.jsmtm-html-to-markdown/assets/js/admin-force-update.js?ver=1.0.0HTML / DOM Fingerprints
name="mtmysc_html_selector"id="mtmysc_slug"window.mtmyscHtmlToMarkdown