
AddQuicktag Security & Risk Analysis
wordpress.org/plugins/addquicktagThis plugin makes it easy to add Quicktags to the html - and visual-editor.
Is AddQuicktag Safe to Use in 2026?
Generally Safe
Score 85/100AddQuicktag has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, 'addquicktag' v2.6.1 exhibits a generally strong security posture, particularly in its handling of database interactions and its limited attack surface. The absence of AJAX handlers, REST API routes, shortcodes, and cron events without authentication checks is commendable, indicating a low risk of direct exploitation through these common entry points. The code exclusively uses prepared statements for SQL queries, a critical security best practice that prevents SQL injection vulnerabilities. Furthermore, the taint analysis revealed no unsanitized paths, suggesting that user-supplied data is not being improperly processed in a way that could lead to code execution or other severe security issues. The presence of nonce and capability checks, while limited, shows an awareness of WordPress security mechanisms.
However, a significant concern arises from the output escaping metrics. With only 14% of 43 outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts into the plugin's output, which would then be executed in the browsers of users interacting with the site. The single file operation, while not inherently risky without further context, warrants attention to ensure it is not being used in a vulnerable manner. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator. This, combined with the low attack surface and secure SQL practices, suggests that the plugin developers are taking security seriously. Nevertheless, the poor output escaping is a critical weakness that needs to be addressed to mitigate XSS risks.
Key Concerns
- Insufficient output escaping
AddQuicktag Security Vulnerabilities
AddQuicktag Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
AddQuicktag Attack Surface
WordPress Hooks 17
Maintenance & Trust
AddQuicktag Maintenance & Trust
Maintenance Signals
Community Trust
AddQuicktag Alternatives
XHE Quicktags
xhe-quicktags
This plugin makes it easy to add Quicktags to the html - and visual-editor.
TCD Classic Editor
tcd-classic-editor
This is a classic editor extension plug-in for TCD users. It is currently offered as a beta board.
Post Editor Buttons Fork
post-editor-buttons-fork
This plugin allows you add your own buttons to the post editor's TEXT mode toolbar.
TinyMCE Table
tinymce-table
Ajoute la création et l'édition des tables à TinyMCE
Manage TinyMCE Editor
manage-tinymce-editor
Add buttons to TinyMCE, WordPress' default visual editor.
AddQuicktag Developer Profile
5 plugins · 101K total installs
How We Detect AddQuicktag
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/addquicktag/inc/class-settings.php/wp-content/plugins/addquicktag/inc/class-tinymce.php/wp-content/plugins/addquicktag/js/add-quicktags.dev.js/wp-content/plugins/addquicktag/js/add-quicktags.jsHTML / DOM Fingerprints
addquicktag_tagsaddquicktag_post_typeaddquicktag_pt_for_js