
Word to html Security & Risk Analysis
wordpress.org/plugins/word-to-htmlDisplay some html from one or more word files from your local webserver or an external webserver.
Is Word to html Safe to Use in 2026?
Generally Safe
Score 85/100Word to html has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "word-to-html" v1.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no known historical vulnerabilities. The attack surface is minimal, with only one shortcode entry point and no unprotected AJAX handlers or REST API routes.
However, significant concerns arise from the code analysis. The most critical finding is that 0% of its 15 output points are properly escaped. This means any data processed and displayed by the plugin is potentially vulnerable to Cross-Site Scripting (XSS) attacks, allowing an attacker to inject malicious scripts into a user's browser.
Furthermore, the plugin has zero nonce checks and zero capability checks. While the static analysis shows no unprotected entry points based on these checks directly, the lack of them in general is a concerning oversight. This, combined with the unescaped output, indicates a potential weakness that could be exploited if an attacker finds a way to trigger the shortcode with malicious input. The absence of critical or high-severity taint flows is a positive sign, but it doesn't mitigate the immediate threat posed by the unescaped output.
Key Concerns
- 0% of outputs properly escaped
- 0 Nonce checks
- 0 Capability checks
Word to html Security Vulnerabilities
Word to html Release Timeline
Word to html Code Analysis
Output Escaping
Word to html Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Word to html Maintenance & Trust
Maintenance Signals
Community Trust
Word to html Alternatives
BlogSync – Convert & Publish Google Docs to WordPress
blogsync
Connect your WordPress site to BlogSync for document-to-post publishing via the BlogSync dashboard.
Seraphinite Post .DOCX Source
seraphinite-post-docx-source
Save your time by automatically converting from .DOCX to content with all WordPress post attributes.
Trendly Content Extractor – DOCX to WordPress Post Converter
trendly-content-extractor
The #1 doc to post converter plugin. Import docx files to WordPress automatically. Convert Word documents to posts with images & SEO optimization.
Robin Image Optimizer – Unlimited Image Optimization & WebP Converter
robin-image-optimizer
Unlimited automatic image optimization for WordPress. Compress images, convert to WebP, and improve site speed without losing image quality.
FOX – Currency Switcher Professional for WooCommerce
woocommerce-currency-switcher
FOX - Currency Switcher Professional for WooCommerce (former name is WOOCS) is currency plugin for woocommerce and multi currency shop, switch & pay
Word to html Developer Profile
3 plugins · 330 total installs
How We Detect Word to html
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/word-to-html/css/wibergsweb.cssHTML / DOM Fingerprints
wrapwordtohtml_create[wordtohtml_create html_class=”wordtohtml” source_files=”sweden.docx” path="maps"]