
wp2epub Security & Risk Analysis
wordpress.org/plugins/wp2epubwp2epub generate ePub files directly from WordPress.
Is wp2epub Safe to Use in 2026?
Generally Safe
Score 85/100wp2epub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp2epub plugin exhibits a mixed security posture. On the positive side, it has a small attack surface with no AJAX handlers or REST API routes, and all its SQL queries utilize prepared statements. Furthermore, there is no recorded vulnerability history, suggesting a potentially well-maintained codebase or a lack of prior scrutiny. However, significant concerns arise from the static analysis. The presence of 'unserialize' as a dangerous function, coupled with 4 high-severity taint flows involving unsanitized paths, points to a critical risk of remote code execution or data manipulation if these paths are exploitable. The extremely low percentage of properly escaped output (7%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into user browsers. The complete absence of nonce checks and capability checks further amplifies these risks, as it means that many actions may not be properly authorized or protected against replay attacks. While the lack of historical CVEs is reassuring, the identified code signals and taint analysis present immediate and severe potential threats that need to be addressed.
Key Concerns
- Dangerous function unserialize used
- High severity taint flows (unsanitized paths)
- Low proper output escaping (potential XSS)
- Missing nonce checks
- Missing capability checks
wp2epub Security Vulnerabilities
wp2epub Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
wp2epub Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
wp2epub Maintenance & Trust
Maintenance Signals
Community Trust
wp2epub Alternatives
Reviews Widgets for Google, Yelp & TripAdvisor
fb-reviews-widget
Combine Facebook recommendations with Google, Yelp and TripAdvisor reviews in a widget, block or shortcode. Build a trusted website!
Insert Headers and Footers Code – HT Script
insert-headers-and-footers-script
This plugin allows you to insert Google analytic code, Facebook pixel code, custom javascript, custom style in your website's header and footer.
Allow ePUB and MOBI formats upload
allow-epub-and-mobi-formats-upload
WordPress does not allow upload ePUB and MOBI formats.
MPL-Publisher — Ebook & Audiobook Creator
mpl-publisher
MPL-Publisher 📚 creates an ebook, print-ready PDF book, EPUB for KDP, Flipbook, or Audiobook MP3 converting your WordPress posts.
Simple Ebook Viewer
simple-ebook-viewer
Embed and display Ebooks in your website.
wp2epub Developer Profile
3 plugins · 80 total installs
How We Detect wp2epub
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp2epub/images/HTML / DOM Fingerprints
w2epubdata-epub<a href="/wp-content/epub/?epub=</a><img src="/wp-content/plugins/wp2epub/images/epub1.png" style="width:44px;height:20px;margin-bottom:0" title="Download epub"/>