
Raw HTML Snippets Security & Risk Analysis
wordpress.org/plugins/raw-html-snippetsCreate a library of raw HTML snippets that you can easily insert into any page/post content using a shortcode.
Is Raw HTML Snippets Safe to Use in 2026?
Generally Safe
Score 85/100Raw HTML Snippets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The raw-html-snippets plugin v2.0.4 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the lack of critical or high-severity vulnerabilities in its history are positive indicators of development attention to security. The static analysis reveals a remarkably small attack surface, with no apparent entry points that are unprotected. Furthermore, the code demonstrates a commitment to secure coding practices by exclusively using prepared statements for SQL queries, and there are no detected file operations or external HTTP requests, which are common vectors for vulnerabilities. The taint analysis also shows no critical or high-severity issues with unsanitized paths, indicating that data inputs are likely handled safely within the analyzed flows.
However, there are areas for potential concern that warrant attention. The most significant weakness identified is the output escaping, where only 46% of outputs are properly escaped. This percentage is considerably low and suggests a risk of cross-site scripting (XSS) vulnerabilities. If user-supplied data is being outputted without sufficient sanitization, an attacker could potentially inject malicious scripts. Additionally, the complete absence of nonce and capability checks across all entry points, while zero in number, is a concern if the plugin were to introduce any AJAX handlers or similar features in the future without implementing these essential security mechanisms. While the current attack surface is zero, this lack of fundamental security checks could become a significant risk if the plugin evolves.
Key Concerns
- Low percentage of properly escaped outputs
- No nonce checks on any entry points
- No capability checks on any entry points
Raw HTML Snippets Security Vulnerabilities
Raw HTML Snippets Code Analysis
Output Escaping
Data Flow Analysis
Raw HTML Snippets Attack Surface
Maintenance & Trust
Raw HTML Snippets Maintenance & Trust
Maintenance Signals
Community Trust
Raw HTML Snippets Alternatives
ACE HTML Block
ace-html-block
Registers a raw html block which uses the ACE Editor. Features include syntax highligting, line numbers, indentation, and HTML validation.
Custom HTML & JS Shortcodes by AnWP.pro
custom-html-js-shortcodes-by-anwppro
Easily create custom HTML and Javascript shortcodes. Syntax highlighting and revisions support.
XML Sitemap Generator for Google
google-sitemap-generator
Generate multiple types of sitemaps to improve SEO and get your website indexed quickly.
WP Sitemap Page
wp-sitemap-page
Add a sitemap on any of your page using the simple shortcode [wp_sitemap_page]. Improve the SEO and navigation of your website.
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Raw HTML Snippets Developer Profile
4 plugins · 2K total installs
How We Detect Raw HTML Snippets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
data-targetjQuery[raw_html_snippet id="