
TinyMCE shortcode Addon Security & Risk Analysis
wordpress.org/plugins/360crest-themeone-tinymce-shortcodesForeigncodes Tinymce Shortcodes, is a wordpress tinymce addon, that jazz up your wordpress post with cool design.
Is TinyMCE shortcode Addon Safe to Use in 2026?
Generally Safe
Score 85/100TinyMCE shortcode Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the '360crest-themeone-tinymce-shortcodes' plugin v1.0.0 exhibits a generally strong security posture. The code analysis shows an absence of dangerous functions, SQL queries executed via prepared statements, and properly escaped output. Furthermore, there are no identified flows with unsanitized paths from the taint analysis, and no recorded vulnerabilities in its history. This indicates that the developers have followed good security practices in these areas.
However, a notable concern is the complete lack of nonce checks across all entry points, which include nine shortcodes. While capability checks are present, the absence of nonces leaves the shortcodes potentially vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker could trick a logged-in user into executing unintended actions through these shortcodes if they are not properly protected. The presence of the TinyMCE library as a bundled component also warrants attention; while not flagged as outdated in this analysis, bundled libraries can become security risks if not maintained and updated.
In conclusion, the plugin demonstrates a solid foundation in secure coding practices regarding data handling and output. The primary weakness lies in the missing CSRF protection mechanisms (nonces) for its shortcodes, which represents a significant, albeit isolated, security risk. The lack of historical vulnerabilities is positive but should not overshadow the need to address the identified CSRF vulnerability.
Key Concerns
- Missing nonce checks on shortcodes
- Bundled library (TinyMCE) - potential for future issues
TinyMCE shortcode Addon Security Vulnerabilities
TinyMCE shortcode Addon Code Analysis
Bundled Libraries
TinyMCE shortcode Addon Attack Surface
Shortcodes 9
WordPress Hooks 7
Maintenance & Trust
TinyMCE shortcode Addon Maintenance & Trust
Maintenance Signals
Community Trust
TinyMCE shortcode Addon Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
WP Shortcode by MyThemeShop
wp-shortcode
WP Shortcode is a premium WP plugin for free, that provides easy to use over 24 shortcodes. You can easily add buttons, alerts, videos and more.
PixCodes
pixcodes
PixCodes offers you a nice interface to add shortcodes into editor.
Arconix Shortcodes
arconix-shortcodes
Arconix Shortcodes provides a number of useful design elements like buttons, boxes, tabs and toggles to help compliment any website.
Rescue Shortcodes
rescue-shortcodes
A lightweight WordPress shortcodes plugin.
TinyMCE shortcode Addon Developer Profile
1 plugin · 0 total installs
How We Detect TinyMCE shortcode Addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/360crest-themeone-tinymce-shortcodes/includes/css/sq_shortcodes_tinymce_style.css/wp-content/plugins/360crest-themeone-tinymce-shortcodes/includes/js/sq_shortcodes_tinymce.js/wp-content/plugins/360crest-themeone-tinymce-shortcodes/css/sq-shortcodes.css/wp-content/plugins/360crest-themeone-tinymce-shortcodes/mce/js/custom.js/wp-content/plugins/360crest-themeone-tinymce-shortcodes/includes/js/sq_shortcodes_tinymce.js/wp-content/plugins/360crest-themeone-tinymce-shortcodes/mce/js/custom.jssq_shortcodes-tctheme_one_shortcode_stylestheme_one_shortcode_jsHTML / DOM Fingerprints
clearsimplebtnboxinfosimplelistone-thirdaccordionButtonaccordionContentAllow shortcodes in widgetsFix ShortcodesClearButtons+8 moredata-mce-placeholder<div class="clear"></div><a href="" class="simplebtn " target="