Classic Editor Media Link Security & Risk Analysis

wordpress.org/plugins/classic-editor-media-link

Plugin adds Media Library Button to the default TinyMCE (Classic Editor) Insert Link dialog

0 active installs v1.0.0 PHP 5.6+ WP 4.3+ Updated Jun 26, 2024
classic-editoreditorimagesmediamedia-library
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Classic Editor Media Link Safe to Use in 2026?

Generally Safe

Score 92/100

Classic Editor Media Link has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "classic-editor-media-link" v1.0.0 demonstrates an excellent security posture based on the provided static analysis. The absence of any detected dangerous functions, SQL queries utilizing prepared statements, and properly escaped output are all strong indicators of secure coding practices. Furthermore, the lack of file operations and external HTTP requests minimizes the potential for common attack vectors. The plugin also appears to have a minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, and notably, zero unprotected entry points.

The vulnerability history is equally impressive, showing no known CVEs, which suggests a history of stable and secure development or a very low profile that hasn't attracted attention for vulnerabilities. The absence of any taint analysis findings further reinforces the conclusion that this plugin is well-developed from a security perspective.

Overall, this plugin presents a very low-risk profile. The strengths significantly outweigh any potential weaknesses. The primary weakness, if it can be called that, is the complete lack of any capability checks or nonce checks, which, while not a direct vulnerability in this context due to the zero attack surface, is a deviation from best practices for WordPress plugins that might interact with users or data in the future. However, given the current analysis, there are no immediate security concerns.

Key Concerns

  • No capability checks detected
  • No nonce checks detected
Vulnerabilities
None known

Classic Editor Media Link Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Classic Editor Media Link Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Classic Editor Media Link Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitclassic-editor-media-link.php:26
actionadmin_enqueue_scriptsclassic-editor-media-link.php:31
Maintenance & Trust

Classic Editor Media Link Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJun 26, 2024
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Classic Editor Media Link Developer Profile

rockstarlab

2 plugins · 60 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Classic Editor Media Link

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/classic-editor-media-link/build/index.asset.php/wp-content/plugins/classic-editor-media-link/build/index.js/wp-content/plugins/classic-editor-media-link/build/index.css
Script Paths
/wp-content/plugins/classic-editor-media-link/build/index.js
Version Parameters
classic-editor-media-link/build/index.js?ver=classic-editor-media-link/build/index.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Classic Editor Media Link