
Abbreviation button for TinyMCE Security & Risk Analysis
wordpress.org/plugins/abbreviation-button-for-tinymceProvides abbreviation button for WordPress TinyMCE visual editor.
Is Abbreviation button for TinyMCE Safe to Use in 2026?
Generally Safe
Score 85/100Abbreviation button for TinyMCE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "abbreviation-button-for-tinymce" plugin version 1.3.7 exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting the plugin's attack surface. Furthermore, the analysis shows no dangerous functions, all SQL queries are prepared, and there are no file operations or external HTTP requests, which are all positive security indicators. The absence of known CVEs in its history further reinforces this positive assessment, suggesting a well-maintained and secure codebase.
However, a significant concern arises from the output escaping analysis, where 100% of the single output identified is not properly escaped. This presents a potential Cross-Site Scripting (XSS) vulnerability if any user-supplied data is reflected in the output without proper sanitization. While the plugin demonstrates good practices in other areas, this lack of output escaping is a critical oversight that could be exploited. The presence of capability checks suggests some attempt at access control, but their effectiveness is not detailed. The bundled TinyMCE library is listed as v1.0, which could potentially be outdated and carry its own unpatched vulnerabilities, though no specific issues are detailed here.
Key Concerns
- 100% of outputs are not properly escaped
- Bundled library (TinyMCE v1.0) may be outdated
Abbreviation button for TinyMCE Security Vulnerabilities
Abbreviation button for TinyMCE Code Analysis
Bundled Libraries
Output Escaping
Abbreviation button for TinyMCE Attack Surface
WordPress Hooks 5
Maintenance & Trust
Abbreviation button for TinyMCE Maintenance & Trust
Maintenance Signals
Community Trust
Abbreviation button for TinyMCE Alternatives
Text Hover
text-hover
Add hover text (aka tooltips) to content in posts. Handy for providing explanations of names, terms, phrases, abbreviations, and acronyms.
Abbreviation Button for the Block Editor
abbreviation-button-for-the-block-editor
Add an abbreviation format button to the formatting toolbar in the block editor.
Acronyms 2
acronyms-2
A plugin to automatically mark up known acronyms and abbreviations in posts and comments. Allows users to manage lists of acronyms through the WordPre …
Accessibility Abbreviation
accessibility-abbreviation
Add abbreviation-tags via TinyMCE to comply with the Web Content Accessibility Guidelines.
Evermore
evermore
Evermore automatically abbreviates all posts when they appear on a multiple-post page such as the main blog page.
Abbreviation button for TinyMCE Developer Profile
24 plugins · 64K total installs
How We Detect Abbreviation button for TinyMCE
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/abbreviation-button-for-tinymce/admin/js/tinymce-abbr-class.jsadmin/js/tinymce-abbr-class.jsHTML / DOM Fingerprints
abbrTranslations