Advanced Classic Editor Security & Risk Analysis

wordpress.org/plugins/best-editor

Advanced Classic Editor - Your powerful WordPress editor, Insert many Icons, Insert Table of contents, etc.

2K active installs v3.1.5 PHP 7.4+ WP 6.0+ Updated Feb 13, 2026
bootstrapeditorfontawesomewordpress-editorwysiwyg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced Classic Editor Safe to Use in 2026?

Generally Safe

Score 100/100

Advanced Classic Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "best-editor" plugin v3.1.5 exhibits a very strong security posture based on the provided static analysis. The complete absence of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) significantly limits the potential attack surface. Furthermore, the code demonstrates excellent security practices, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The lack of file operations and external HTTP requests further reinforces this robust security profile. The plugin's vulnerability history is also clean, with zero known CVEs, indicating a history of secure development or diligent patching if issues have arisen in the past.

While the static analysis reveals no immediate vulnerabilities, it's important to note the absence of specific security checks like nonce checks on potential entry points, even though none were found. The presence of three capability checks is positive, but the overall lack of other common security mechanisms on any identified entry points (which are zero) means that if an entry point were to be introduced in a future version, it might lack these protections by default. However, based on the current data, the plugin appears to be exceptionally secure and well-developed, with no specific risks identified. Its strengths lie in its minimal attack surface and adherence to secure coding practices for the features it currently implements.

Vulnerabilities
None known

Advanced Classic Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Advanced Classic Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

100% escaped5 total outputs
Attack Surface

Advanced Classic Editor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_menuincludes\BestEditor\class-best-editor-options.php:52
actionadmin_noticesincludes\BestEditor\class-best-editor-options.php:55
actionadmin_initincludes\BestEditor\class-best-editor-options.php:57
actionadmin_enqueue_scriptsincludes\BestEditor\class-best-editor.php:169
actionwp_enqueue_scriptsincludes\BestEditor\class-best-editor.php:172
filtermce_external_pluginsincludes\BestEditor\class-best-editor.php:291
filtermce_buttonsincludes\BestEditor\class-best-editor.php:300
filtermce_buttons_2includes\BestEditor\class-best-editor.php:301
filtermce_buttons_3includes\BestEditor\class-best-editor.php:302
filtertiny_mce_before_initincludes\BestEditor\class-best-editor.php:304
actionadmin_headincludes\BestEditor\class-best-editor.php:504
Maintenance & Trust

Advanced Classic Editor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 13, 2026
PHP min version7.4
Downloads41K

Community Trust

Rating86/100
Number of ratings9
Active installs2K
Developer Profile

Advanced Classic Editor Developer Profile

DediData

4 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced Classic Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/best-editor/assets/public/css/style.rtl.css/wp-content/plugins/best-editor/assets/public/css/style.css/wp-content/plugins/best-editor/assets/public/js/script.js/wp-content/plugins/best-editor/assets/admin/css/style.rtl.css/wp-content/plugins/best-editor/assets/admin/css/style.css/wp-content/plugins/best-editor/assets/admin/js/script.js
Script Paths
/wp-content/plugins/best-editor/assets/fontawesome-6.5.1/js/all.min.js/wp-content/plugins/best-editor/assets/bootstrap-5.3.3/js/bootstrap.min.js
Version Parameters
best-editor/style.css?ver=best-editor-rtl/style.rtl.css?ver=best-editor/script.js?ver=font-awesomebootstrap-5.3.3/css/bootstrap.rtl.min.cssbootstrap-5.3.3/css/bootstrap.min.cssbootstrapbootstrap-5.3.3/js/bootstrap.min.js

HTML / DOM Fingerprints

CSS Classes
tox-tinymcetox
HTML Comments
<!-- The TinyMCE editor --><!-- The TinyMCE editor --><!-- The TinyMCE editor -->
Data Attributes
data-editor-iddata-tinymce-id
JS Globals
tinymceBestEditor
FAQ

Frequently Asked Questions about Advanced Classic Editor