Advanced TinyMCE Configuration Security & Risk Analysis

wordpress.org/plugins/advanced-tinymce-configuration

Set advanced TinyMCE options for the classic block and classic editor.

10K active installs v1.6 PHP + WP 3.9+ Updated Apr 10, 2023
editortinymcewysiwyg
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced TinyMCE Configuration Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced TinyMCE Configuration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "advanced-tinymce-configuration" plugin version 1.6 demonstrates a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, unpatched vulnerabilities, or recorded common vulnerability types in its history suggests a history of responsible development and patching. Furthermore, the code analysis reveals a commendable lack of dangerous functions, raw SQL queries, file operations, and external HTTP requests, all of which are significant risk reduction factors. The presence of nonces and capability checks, even with a limited attack surface, further bolsters its security. However, a notable concern lies in the output escaping. With 32 total outputs, only 34% being properly escaped indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While the attack surface is currently reported as zero, this low output escaping rate presents a latent risk that could be exploited if any of the entry points were to become exposed or if the plugin's functionality were to be expanded in the future without adequate sanitization.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Advanced TinyMCE Configuration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Advanced TinyMCE Configuration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
11 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

34% escaped32 total outputs
Attack Surface

Advanced TinyMCE Configuration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filtertiny_mce_before_initadv-mce-config.php:34
actionadmin_head-settings_page_advanced-tinymce-configurationadv-mce-config.php:54
filterplugin_action_linksadv-mce-config.php:178
actionadmin_menuadv-mce-config.php:194
Maintenance & Trust

Advanced TinyMCE Configuration Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedApr 10, 2023
PHP min version
Downloads210K

Community Trust

Rating96/100
Number of ratings12
Active installs10K
Developer Profile

Advanced TinyMCE Configuration Developer Profile

Andrew Ozz

6 plugins · 2.0M total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
3424 days
View full developer profile
Detection Fingerprints

How We Detect Advanced TinyMCE Configuration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-tinymce-configuration/adv-mce-config.js/wp-content/plugins/advanced-tinymce-configuration/css/tinymce-custom.css
Script Paths
/wp-content/plugins/advanced-tinymce-configuration/adv-mce-config.js
Version Parameters
advanced-tinymce-configuration/adv-mce-config.js?ver=advanced-tinymce-configuration/css/tinymce-custom.css?ver=

HTML / DOM Fingerprints

CSS Classes
advmceconfadvmceconf-wrapadvmceconf-exampleadvmceconf-formadvmceconf-tableadvmceconf-defaultsadvmceconf-code-links
Data Attributes
advmceconf-save-options
JS Globals
advmceconf_show_defaults
FAQ

Frequently Asked Questions about Advanced TinyMCE Configuration