
Worddown Security & Risk Analysis
wordpress.org/plugins/worddownExport WordPress pages and posts to markdown files for AI chatbots with support for custom page builders and multilingual content.
Is Worddown Safe to Use in 2026?
Generally Safe
Score 100/100Worddown has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'worddown' v1.1.3 exhibits a strong security posture based on the provided static analysis. The absence of direct vulnerabilities in SQL queries, the consistent 100% output escaping, and the robust use of capability checks across all identified REST API routes are commendable practices. The plugin also avoids common pitfalls like bundled libraries and external HTTP requests, further reducing its attack surface. The vulnerability history being completely clear of any recorded CVEs is a significant positive indicator of past security diligence.
While the static analysis reveals a clean slate regarding dangerous functions and taint flows, and no unpatched vulnerabilities are known, the data does present some areas for consideration. The lack of nonce checks across the identified entry points (though they are protected by capability checks for REST API) could be a potential, albeit minor, concern in specific scenarios if the capability checks were to be bypassed or misconfigured. The presence of file operations, while not inherently risky, warrants attention to ensure these operations are performed securely and do not introduce vulnerabilities. Overall, 'worddown' v1.1.3 appears to be a well-secured plugin with minimal immediate risks, but continued vigilance and review of file operation implementations are advisable.
Key Concerns
- No nonce checks on entry points
- Presence of file operations
Worddown Security Vulnerabilities
Worddown Code Analysis
SQL Query Safety
Output Escaping
Worddown Attack Surface
REST API Routes 12
WordPress Hooks 19
Scheduled Events 3
Maintenance & Trust
Worddown Maintenance & Trust
Maintenance Signals
Community Trust
Worddown Alternatives
LLM Markdown – Expose Content as .md
llm-markdown
Expose WordPress posts and pages as real .md URLs with YAML front matter for LLMs, AI ingestion, and headless workflows.
AI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o
aibuddy-openai-chatgpt
AI Bud an AI Content & Image Generation, AI ChatBot, ChatGPT, OpenAI, Perplexity, Gemini, GPT-4o, LLAMA, Mistral
MxChat – AI Chatbot & Content Generation for WordPress
mxchat-basic
The best free AI chatbot and content generation plugin for WordPress. Train ChatGPT, Claude, Gemini, or Grok on your website content.
AI Product Tools – Bulk Product Content Generator & AI Toolkit for WooCommerce
ai-product-tools
All-in-One AI Suite for WooCommerce: Bulk generate descriptions, titles, tags, FAQs, SEO Meta & AI Chatbot via OpenAI, Gemini, Claude & OpenRouter
StoreAgent – WooCommerce AI Chatbot & AI Content Tools
storeagent-ai-for-woocommerce
WooCommerce AI Chatbot for stores with built-in AI content tools. Generate product descriptions, answer customer questions & more with AI.
Worddown Developer Profile
2 plugins · 40 total installs
How We Detect Worddown
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/worddown/dist/resources/assets/js/admin.tsx/wp-content/plugins/worddown/dist/config('app.version')HTML / DOM Fingerprints
worddown_variables/worddown/v1/dashboard