
Remove layout destroying HTML-Tags Security & Risk Analysis
wordpress.org/plugins/remove-layout-destroying-html-tagsCopy&Paste Cleaner. Cleanup the code in post and page editor after using copy&paste content from different sources and automatic saving.
Is Remove layout destroying HTML-Tags Safe to Use in 2026?
Generally Safe
Score 100/100Remove layout destroying HTML-Tags has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'remove-layout-destroying-html-tags' plugin v0.4.2 exhibits a generally strong security posture based on the provided static analysis. The plugin avoids dangerous functions, all SQL queries are properly prepared, and the vast majority of output is correctly escaped. Furthermore, there are no recorded vulnerabilities (CVEs) for this plugin, and the taint analysis revealed no problematic data flows. The presence of a nonce check on its single AJAX handler is a positive indicator of security awareness.
However, a notable concern arises from the complete absence of capability checks on its AJAX handler. While it has a nonce check, which prevents cross-site request forgery, it does not verify if the logged-in user has the necessary permissions to execute the AJAX action. This could potentially allow any authenticated user, regardless of their role, to trigger the plugin's functionality, which might be undesirable or lead to unexpected consequences if the AJAX action has side effects. The plugin also bundles TinyMCE, and while no specific issues are flagged here, relying on bundled libraries can sometimes introduce risks if they are outdated or have their own vulnerabilities that are not addressed.
In conclusion, the plugin demonstrates good practices in several critical areas like SQL and output sanitization and boasts a clean vulnerability history. The primary weakness lies in the lack of capability checks for its AJAX endpoint. Addressing this would significantly bolster its security. The absence of other common vulnerabilities suggests a well-developed plugin, but the permission handling on the AJAX endpoint is a key area for improvement.
Key Concerns
- Missing capability check on AJAX handler
Remove layout destroying HTML-Tags Security Vulnerabilities
Remove layout destroying HTML-Tags Code Analysis
Bundled Libraries
Output Escaping
Remove layout destroying HTML-Tags Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Remove layout destroying HTML-Tags Maintenance & Trust
Maintenance Signals
Community Trust
Remove layout destroying HTML-Tags Alternatives
Cleanup HTML
clean-html
Adds a button to your classic editor visual toolbar that when clicked strips all div, 'table', span tags from your post HTML code -- those a …
Rich Text Editor
richtexteditor
This plugin integrates your Wordpress with RichTextEditor - the most powerful online wysiwyg content editor.
HTML Regex Replace
html-regex-replace
Replace any html you write in editor (Visual or HTML) with pre-defined string. Use Regexp to define patterns for replacement.
Secure Login
secure-login
Secure, 2 step Verification for WordPress login, via One Time Pin (OTP).
Smart Editor
smart-editor
WYSIWYG(What You See Is What You Get.) HTML5 Editor,
Remove layout destroying HTML-Tags Developer Profile
1 plugin · 100 total installs
How We Detect Remove layout destroying HTML-Tags
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/remove-layout-destroying-html-tags/js/rldht_tinymce-cleanup-button.js/wp-content/plugins/remove-layout-destroying-html-tags/js/rldht_gutenberg-block.js/wp-content/plugins/remove-layout-destroying-html-tags/images/rldht_icon.svgHTML / DOM Fingerprints
data-rldht-noncedata-rldht-ajaxurldata-rldht-iconurlwindow.rldht_vars