
Classic Editor Security & Risk Analysis
wordpress.org/plugins/classic-editorEnables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Is Classic Editor Safe to Use in 2026?
Generally Safe
Score 100/100Classic Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Classic Editor plugin, version 1.6.7, demonstrates a strong security posture based on the provided static analysis. The absence of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) significantly limits the potential attack surface. Furthermore, the code signals indicate good development practices, with no dangerous functions, all SQL queries utilizing prepared statements, and a high percentage of output being properly escaped. The presence of nonce and capability checks also contributes to a more secure implementation, preventing unauthorized actions. The plugin's vulnerability history is clean, with zero recorded CVEs, suggesting a commitment to security and diligent maintenance over time.
While the static analysis reveals no immediate threats, the taint analysis reporting zero flows is noteworthy. In complex plugins, even a single flow with unsanitized input can lead to vulnerabilities. The low number of total flows analyzed (0) might indicate a relatively small code base or that the taint analysis tool may not have been able to analyze all potential data flow paths. However, based on the provided data, there are no specific security concerns stemming from the code analysis or historical vulnerabilities that warrant deduction. The plugin appears to be well-developed from a security perspective, with no evident weaknesses in its current version.
Classic Editor Security Vulnerabilities
Classic Editor Code Analysis
Output Escaping
Classic Editor Attack Surface
WordPress Hooks 30
Maintenance & Trust
Classic Editor Maintenance & Trust
Maintenance Signals
Community Trust
Classic Editor Alternatives
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Disable Gutenberg
disable-gutenberg
Disable Gutenberg Block Editor and restore the Classic Editor and original Edit Post screen (TinyMCE, meta boxes, etc.).
Classic Editor and Classic Widgets
classic-editor-and-classic-widgets
Disables Gutenberg editor totally everywhere and enables Classic Editor and Classic Widgets.
Enable Classic Editor & Widgets
enable-classic-editor
A simple & lightweight plugin to enable the classic editor on WordPress with advanced configuration options.
Guten Free Options
guten-free-options
Gutenberg Free Options for your WordPressed Burger err I mean Editor.
Classic Editor Developer Profile
34 plugins · 14.9M total installs
How We Detect Classic Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/classic-editor/assets/css/classic-editor.css/wp-content/plugins/classic-editor/assets/js/classic-editor.js/wp-content/plugins/classic-editor/assets/js/classic-editor.jsclassic-editor/assets/css/classic-editor.css?ver=classic-editor/assets/js/classic-editor.js?ver=HTML / DOM Fingerprints
classic-editor-plugin-settings<!-- Classic Editor: Settings UI --><!-- Classic Editor: Remember Editor Preference -->data-classic-editor-settingsclassicEditorSettings