
WP-MarkupCollection Security & Risk Analysis
wordpress.org/plugins/wp-markupcollectionThis plugin allows you to write posts using Markdown, DokuWiki, MediaWiki, reStructuredText, textile, HatenaSyntax, BBcode, etc.
Is WP-MarkupCollection Safe to Use in 2026?
Generally Safe
Score 85/100WP-MarkupCollection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-markupcollection plugin v1.1.2 presents a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and exhibits no external HTTP requests or file operations, which are common vectors for attacks. The static analysis also indicates a complete lack of REST API routes, AJAX handlers, shortcodes, and cron events, suggesting a very limited attack surface and minimal exposure to common WordPress entry points.
However, significant concerns arise from the code analysis. The presence of the `create_function` function is a critical red flag, as it is deprecated and known to be a source of security vulnerabilities, particularly when used with untrusted input. Furthermore, a complete lack of output escaping on all nine identified output points means that any data processed by the plugin could potentially be rendered unsafely, leading to cross-site scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks, coupled with the `create_function` issue, opens the door for various insecure operations.
Given the lack of historical vulnerabilities, it might seem reassuring. However, this could also indicate that the plugin hasn't been thoroughly audited or that its limited functionality hasn't exposed latent issues. The current state of the code, with `create_function` and universally unescaped output, represents a substantial risk that is not mitigated by the absence of known CVEs. The plugin should be updated to address these critical code-level weaknesses.
Key Concerns
- Use of deprecated and dangerous function create_function
- Output escaping not properly implemented
- Lack of nonce checks
- Lack of capability checks
WP-MarkupCollection Security Vulnerabilities
WP-MarkupCollection Code Analysis
Dangerous Functions Found
Output Escaping
WP-MarkupCollection Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP-MarkupCollection Maintenance & Trust
Maintenance Signals
Community Trust
WP-MarkupCollection Alternatives
Import Markdown – Versatile Markdown Importer
import-markdown
Import Markdown lets you easily generates posts based on Markdown files.
Markup Markdown
markup-markdown
Disable Wordpress's native Gutenberg or TinyMCE editor in favor of a Markdown editor.
Markdown Editor (Formerly Dark Mode)
dark-mode
Quickly edit content in your WordPress site by getting an immersive, peaceful and natural writing experience with the coolest editor.
Ultimate Markdown – Markdown Editor, Importer, & Exporter
ultimate-markdown
Generate block-based articles from a Markdown file, bulk import and export Markdown documents, create Markdown documents from an editor, and more.
RDP Wiki Embed
rdp-wiki-embed
RDP Wiki Embed lets you embed content from MediaWiki sites.
WP-MarkupCollection Developer Profile
1 plugin · 10 total installs
How We Detect WP-MarkupCollection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-markupcollection/js/dist/wp-markup-collection.js/wp-content/plugins/wp-markupcollection/js/dist/wp-markup-collection.jswp-markupcollection/js/dist/wp-markup-collection.js?ver=HTML / DOM Fingerprints
wp-markup-collection