
Preserved HTML Editor Markup Plus Security & Risk Analysis
wordpress.org/plugins/preserved-html-editor-markup-plusPreserves HTML and developer edits in HTML AND WYSIWYG tab. Supports inline scripts/css, JavaScript code blocks and HTML5 content editing
Is Preserved HTML Editor Markup Plus Safe to Use in 2026?
Generally Safe
Score 85/100Preserved HTML Editor Markup Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'preserved-html-editor-markup-plus' plugin version 1.5.4 exhibits a generally good security posture based on the static analysis provided. The absence of any known CVEs and a clean vulnerability history are significant strengths. The code also demonstrates good practices with all SQL queries utilizing prepared statements and a nonce check present. However, there are areas for improvement. The low percentage of properly escaped output (13%) indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. Additionally, the lack of capability checks on the single AJAX handler is a concern, as it means any authenticated user could potentially trigger its functionality, regardless of their role or permissions. The absence of critical taint flows and dangerous functions is positive, suggesting that while output escaping is weak, the plugin doesn't appear to be directly handling sensitive data in a highly insecure manner or executing dangerous operations.
Key Concerns
- Low output escaping percentage
- AJAX handler without capability checks
Preserved HTML Editor Markup Plus Security Vulnerabilities
Preserved HTML Editor Markup Plus Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Preserved HTML Editor Markup Plus Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Preserved HTML Editor Markup Plus Maintenance & Trust
Maintenance Signals
Community Trust
Preserved HTML Editor Markup Plus Alternatives
Preserved HTML Editor Markup
preserved-html-editor-markup
Preserves white space and developer edits in HTML AND WYSIWYG tab. Supports inline scripts/css, JavaScript code blocks and HTML5 content editing
Toggle wpautop
toggle-wpautop
Easily disable the default wpautop filter on a post by post basis.
Contact Form 7 Syntax Highlighting
cf7-ace-syntax-highlighting
Adds syntax higlighting to the Contact Form 7 admin screens. Requires the Contact Form 7 plugin.
HTML Editor for Contact Form 7
cf7-coder
Add HTML editor to Contact Form 7 with code highlighter and extended form options.
Empty P Tag
empty-p-tag
This plugin hides empty paragraphs and make your butyfull design without breaking design.
Preserved HTML Editor Markup Plus Developer Profile
3 plugins · 4K total installs
How We Detect Preserved HTML Editor Markup Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/preserved-html-editor-markup-plus/css/preserved_markup_plus.css/wp-content/plugins/preserved-html-editor-markup-plus/js/preserved_markup_plus.js/wp-content/plugins/preserved-html-editor-markup-plus/js/preserved_markup_plus.jspreserved-html-editor-markup-plus/css/preserved_markup_plus.css?ver=preserved-html-editor-markup-plus/js/preserved_markup_plus.js?ver=HTML / DOM Fingerprints
<!-- Preserve whitespace within this comment block -->data-editor_insert_pemc2_tinymce_init