Mytory Markdown for Dropbox Security & Risk Analysis

wordpress.org/plugins/mytory-markdown-for-dropbox

Link with Dropbox, select markdown file. Then, post content will be updated. It's Cool.

10 active installs v1.0.4 PHP + WP + Updated Unknown
dropboxmarkdown
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Mytory Markdown for Dropbox Safe to Use in 2026?

Generally Safe

Score 100/100

Mytory Markdown for Dropbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'mytory-markdown-for-dropbox' v1.0.4 exhibits a concerning security posture due to several critical vulnerabilities identified in the static analysis. The presence of two unprotected AJAX handlers significantly expands the attack surface for potential unauthorized access and execution. Furthermore, the use of dangerous functions like 'create_function' and 'exec' raises red flags for code injection risks. The complete lack of output escaping means that any data processed or displayed by the plugin is susceptible to Cross-Site Scripting (XSS) attacks, a severe risk for user data and site integrity.

The vulnerability history being clean is a positive indicator, suggesting that past development might have been more secure or that the plugin has not been extensively targeted. However, this cannot mitigate the severe, inherent risks exposed by the current code analysis. The taint analysis, while not revealing critical or high-severity unsanitized flows, doesn't fully offset the other identified weaknesses. The overall assessment points to a plugin that requires immediate attention to address its insecure coding practices, particularly regarding input validation, output sanitization, and secure handling of AJAX requests.

Key Concerns

  • Unprotected AJAX handlers
  • Dangerous function: create_function
  • Dangerous function: exec
  • SQL queries without prepared statements
  • No output escaping detected
  • No nonce checks on AJAX handlers
  • Flows with unsanitized paths (taint analysis)
Vulnerabilities
None known

Mytory Markdown for Dropbox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mytory Markdown for Dropbox Code Analysis

Dangerous Functions
2
Raw SQL Queries
1
0 prepared
Unescaped Output
28
0 escaped
Nonce Checks
0
Capability Checks
6
File Operations
3
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

create_function$this->utf8_strlen = create_function('$text', 'return preg_match_all(markdown.php:1763
execexec($command, $result, $return_var);MM4DMultimarkdown.php:16

SQL Query Safety

0% prepared1 total queries

Output Escaping

0% escaped28 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
getConvertedContent (main.php:351)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Mytory Markdown for Dropbox Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 3

authwp_ajax_mm4d_get_converted_contentmain.php:43
authwp_ajax_mm4d_delete_optionsmain.php:44
authwp_ajax_mm4d_update_in_clientmain.php:45
WordPress Hooks 22
actionplugins_loadedmain.php:36
actionadd_meta_boxesmain.php:37
actionadmin_menumain.php:38
actionadmin_initmain.php:39
actionsave_postmain.php:40
actionadmin_enqueue_scriptsmain.php:41
actionwp_enqueue_scriptsmain.php:42
actionadmin_bar_menumain.php:50
filterthe_contentmarkdown.php:90
filterthe_content_rssmarkdown.php:91
filterget_the_excerptmarkdown.php:92
filterget_the_excerptmarkdown.php:93
filterthe_excerptmarkdown.php:94
filterthe_excerpt_rssmarkdown.php:95
filterthe_contentmarkdown.php:99
filterget_the_excerptmarkdown.php:100
filterpre_comment_contentmarkdown.php:127
filterpre_comment_contentmarkdown.php:128
filterpre_comment_contentmarkdown.php:129
filterget_comment_textmarkdown.php:130
filterget_comment_excerptmarkdown.php:131
filterget_comment_excerptmarkdown.php:132
Maintenance & Trust

Mytory Markdown for Dropbox Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings5
Active installs10
Developer Profile

Mytory Markdown for Dropbox Developer Profile

An, Hyeong-woo

3 plugins · 130 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mytory Markdown for Dropbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mytory-markdown-for-dropbox/js/bundle.js/wp-content/plugins/mytory-markdown-for-dropbox/js-lib/remodal/remodal.min.js/wp-content/plugins/mytory-markdown-for-dropbox/js-lib/remodal/remodal.css/wp-content/plugins/mytory-markdown-for-dropbox/js-lib/remodal/remodal-default-theme.css/wp-content/plugins/mytory-markdown-for-dropbox/style.css
Script Paths
https://unpkg.com/dropbox/dist/Dropbox-sdk.min.js/wp-content/plugins/mytory-markdown-for-dropbox/js-lib/remodal/remodal.min.js/wp-content/plugins/mytory-markdown-for-dropbox/js/bundle.js
Version Parameters
mytory-markdown-for-dropbox/js/bundle.js?ver=mytory-markdown-for-dropbox/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
remodal-overlayremodal-wrapperremodal-contentremodal-headerremodal-bodyremodal-footer
Data Attributes
data-remodal-iddata-remodal-close
JS Globals
Dropboxmm4d
REST Endpoints
/wp-json/mytory-markdown-for-dropbox/v1/settings
FAQ

Frequently Asked Questions about Mytory Markdown for Dropbox