
Averroes Security & Risk Analysis
wordpress.org/plugins/averroesA Gutenberg compatible markdown editor. Write in Markdown, edit in Markdown and preview in HTML.
Is Averroes Safe to Use in 2026?
Generally Safe
Score 85/100Averroes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'averroes' v1.1.1 demonstrates an exceptionally strong security posture based on the provided static analysis and vulnerability history. The complete absence of identified entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The lack of file operations, external HTTP requests, and the absence of non-checked or capability-checked functions further bolster its security. The taint analysis also shows no identified flows with unsanitized paths, indicating no apparent injection vulnerabilities.
The vulnerability history is equally impressive, with zero known CVEs recorded. This suggests a history of secure development and maintenance, or perhaps limited adoption and testing leading to undiscovered vulnerabilities. However, based solely on the provided data, there are no specific weaknesses to highlight, and the plugin appears to be exceptionally secure. The primary concern is the complete lack of any identified security mechanisms like nonce or capability checks, which, while not a problem in this specific analysis due to the zero attack surface, could become a critical weakness if any new entry points were introduced without these safeguards. Therefore, while the current state is excellent, future development should prioritize maintaining this secure approach and implementing appropriate checks if the attack surface expands.
Key Concerns
- No Nonce Checks
- No Capability Checks
Averroes Security Vulnerabilities
Averroes Release Timeline
Averroes Code Analysis
Averroes Attack Surface
Maintenance & Trust
Averroes Maintenance & Trust
Maintenance Signals
Community Trust
Averroes Alternatives
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Averroes Developer Profile
3 plugins · 140 total installs
How We Detect Averroes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/averroes/css/editor.css/wp-content/plugins/averroes/css/style.css/wp-content/plugins/averroes/js/editor.js/wp-content/plugins/averroes/js/i18n.js/wp-content/plugins/averroes/js/editor.js/wp-content/plugins/averroes/js/i18n.jsaverroes/css/editor.css?ver=averroes/css/style.css?ver=averroes/js/editor.js?ver=averroes/js/i18n.js?ver=