
Readme Generator Security & Risk Analysis
wordpress.org/plugins/readme-generatorA simple plugin to convert a HTML post or page content into a plugin readme.txt file.
Is Readme Generator Safe to Use in 2026?
Generally Safe
Score 85/100Readme Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "readme-generator" v1.0.2 plugin exhibits a mixed security posture. While it demonstrates strengths in its use of prepared statements for SQL queries and a clean vulnerability history with no known CVEs, significant concerns arise from its attack surface and output handling. The presence of an unprotected AJAX handler presents a direct pathway for potential abuse if not properly secured by the application itself. The code also utilizes a dangerous function, `preg_replace(/e)`, which can be exploited for code injection under certain circumstances. Furthermore, the complete lack of output escaping for all identified output points is a critical weakness, opening the door to Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while showing no critical or high severity flows, indicates two flows with unsanitized paths, which could potentially lead to issues if combined with other weaknesses. The plugin's history of zero vulnerabilities is a positive indicator, suggesting diligent development practices in the past. However, the current static analysis reveals significant weaknesses that, if exploited, could be severe. The absence of proper output escaping is particularly alarming and represents a major security risk that needs immediate attention, even in the absence of past reported vulnerabilities.
Key Concerns
- Unprotected AJAX handler
- Dangerous function: preg_replace(/e)
- All output improperly escaped
- Flows with unsanitized paths detected
Readme Generator Security Vulnerabilities
Readme Generator Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Readme Generator Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Readme Generator Maintenance & Trust
Maintenance Signals
Community Trust
Readme Generator Alternatives
No alternatives data available yet.
Readme Generator Developer Profile
2 plugins · 20 total installs
How We Detect Readme Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/readme-generator/readme-gen.js/wp-content/plugins/readme-generator/readme-gen.css/wp-content/plugins/readme-generator/readme-gen.jsreadme-generator/readme-gen.css?ver=readme-generator/readme-gen.js?ver=HTML / DOM Fingerprints
readme-gen-ajax-feedback<!-- Widget to display the form -->data-rg-post-iddata-rg-post-typedata-rg-post-titledata-rg-post-contentdata-rg-post-excerptdata-rg-post-modified+27 morereadme_gen