
WPMK PDF Generator Security & Risk Analysis
wordpress.org/plugins/wpmk-pdf-generatorThis Free Plugin will provide you to add download html to pdf
Is WPMK PDF Generator Safe to Use in 2026?
Use With Caution
Score 63/100WPMK PDF Generator has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wpmk-pdf-generator" plugin v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing all SQL queries with prepared statements, and not making external HTTP requests. The attack surface is relatively small, with only one shortcode and no directly exploitable AJAX or REST API entry points without authentication checks. However, significant concerns arise from the static analysis. A substantial percentage of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. Furthermore, the taint analysis revealed a flow with an unsanitized path, indicating a potential risk for directory traversal or similar file system vulnerabilities, even though no specific critical or high severity issues were flagged in this analysis.
The vulnerability history is a major red flag. The plugin has a known medium severity CVE that remains unpatched. This, coupled with the mention of Cross-Site Request Forgery (CSRF) as a common vulnerability type in its history, suggests a pattern of security weaknesses. The fact that a medium vulnerability is unpatched in this version is concerning and poses an immediate risk to users. While the current analysis doesn't reveal critical flaws, the unpatched CVE and the potential for XSS and path traversal issues from the static analysis, combined with historical CSRF vulnerabilities, indicate that this plugin should be treated with caution. Users should be aware of the unpatched vulnerability and the potential for other issues due to insufficient output escaping and unsanitized path flows.
Key Concerns
- Unpatched CVE present
- Insufficient output escaping (37% proper)
- Flows with unsanitized paths
- No nonce checks
- No capability checks
WPMK PDF Generator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPMK PDF Generator <= 1.0.1 - Cross-Site Request Forgery
WPMK PDF Generator Code Analysis
Output Escaping
Data Flow Analysis
WPMK PDF Generator Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
WPMK PDF Generator Maintenance & Trust
Maintenance Signals
Community Trust
WPMK PDF Generator Alternatives
WP PDF Generator
wp-pdf-generator
Simply helps you to get your web page download as pdf
PDF Poster – Display PDF Files with Custom Viewer
pdf-poster
PDF Poster lets you embed PDF files in WordPress using a responsive viewer and block support, including full-screen, download, and print options.
PDF & Print by BestWebSoft – WordPress Posts and Pages PDF Generator Plugin
pdf-print
Generate PDF files and print WordPress posts/pages. Customize document header/footer styles and appearance.
DK PDF – WordPress PDF Generator
dk-pdf
DK PDF allows your site visitors generate PDF files from WordPress posts, pages, custom post types and WooCommerce products using a button.
PDF Generator for WordPress Elementor
pdf-generator-addon-for-elementor-page-builder
The ultimate WordPress PDF generator for Elementor. Easily export to PDF, add a download button, and convert WooCommerce products to PDF.
WPMK PDF Generator Developer Profile
5 plugins · 100 total installs
How We Detect WPMK PDF Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpmk-pdf-generator/assets/css/style.css/wp-content/plugins/wpmk-pdf-generator/assets/js/es6-promise.auto.min.js/wp-content/plugins/wpmk-pdf-generator/assets/js/jspdf.min.js/wp-content/plugins/wpmk-pdf-generator/assets/js/html2canvas.min.js/wp-content/plugins/wpmk-pdf-generator/assets/js/html2pdf.min.js/wp-content/plugins/wpmk-pdf-generator/assets/js/es6-promise.auto.min.js/wp-content/plugins/wpmk-pdf-generator/assets/js/jspdf.min.js/wp-content/plugins/wpmk-pdf-generator/assets/js/html2canvas.min.js/wp-content/plugins/wpmk-pdf-generator/assets/js/html2pdf.min.jswpmk-pdf-generator/assets/css/style.css?ver=wpmk-pdf-generator/assets/js/es6-promise.auto.min.js?ver=wpmk-pdf-generator/assets/js/jspdf.min.js?ver=wpmk-pdf-generator/assets/js/html2canvas.min.js?ver=wpmk-pdf-generator/assets/js/html2pdf.min.js?ver=HTML / DOM Fingerprints
<!-- Here wpmk pdf base class that hold plugin
functions and data. this class as treat
as auto-run. --><!-- Here we define plugin action hook
it will add link in plugin action bar
and all plugin setting and saving data --><!-- Here active wpmk pdf
it is plugin init and
hold all functions --><!-- Here we are installing plugin options
and also plugin require data -->+7 morearia-label="Plugin Additional Links Settings"aria-label="Plugin Additional Links Documentation"aria-label="Plugin Additional Links Developer"[wpmk_pdf_generate]