
WP HTML Imports Helper Security & Risk Analysis
wordpress.org/plugins/wp-html-imports-helperAdd support for HTML Imports enqueue
Is WP HTML Imports Helper Safe to Use in 2026?
Generally Safe
Score 85/100WP HTML Imports Helper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-html-imports-helper plugin, in version 0.1, presents a generally positive security posture based on the provided static analysis. The plugin exhibits zero known vulnerabilities, a clean vulnerability history, and no dangerous functions identified. The code analysis reveals a limited attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing potential entry points for attackers. Furthermore, the single SQL query utilizes prepared statements, which is a strong security practice. However, there are areas for concern. A significant weakness lies in the output escaping, with only 40% of outputs being properly escaped. This means there's a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly echoed without sanitization. Additionally, the complete absence of nonce checks and capability checks across all entry points, though currently unexploited due to the small attack surface, represents a significant omission in core WordPress security practices. This could become a critical oversight if the plugin's functionality expands or if new entry points are introduced without these essential security layers.
Key Concerns
- Poor output escaping practices
- Missing nonce checks
- Missing capability checks
WP HTML Imports Helper Security Vulnerabilities
WP HTML Imports Helper Code Analysis
SQL Query Safety
Output Escaping
WP HTML Imports Helper Attack Surface
WordPress Hooks 1
Maintenance & Trust
WP HTML Imports Helper Maintenance & Trust
Maintenance Signals
Community Trust
WP HTML Imports Helper Alternatives
No alternatives data available yet.
WP HTML Imports Helper Developer Profile
6 plugins · 270 total installs
How We Detect WP HTML Imports Helper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-html-imports-helper/class.wp-documents.php/wp-content/plugins/wp-html-imports-helper/functions.wp-documents.php