Comment Form with TinyMCE Security & Risk Analysis

wordpress.org/plugins/comment-form-tinymce

Comment Form with TinyMCE

10 active installs v1.0.0 PHP 5.6+ WP 5.0+ Updated Unknown
comment-form-tinymce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Comment Form with TinyMCE Safe to Use in 2026?

Generally Safe

Score 100/100

Comment Form with TinyMCE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "comment-form-tinymce" v1.0.0 plugin demonstrates a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the plugin's attack surface. The code also shows excellent practices regarding SQL queries, output escaping, and a complete absence of file operations or external HTTP requests. Furthermore, the lack of taint analysis findings suggests no obvious vulnerabilities related to unsanitized data flows. The vulnerability history is also clean, with no recorded CVEs, indicating a lack of known security issues.

However, the analysis does highlight a potential concern with the bundled library, TinyMCE v1.0.0. If this version is outdated and has known vulnerabilities, it could represent a risk that is not directly visible in the plugin's own code. The absence of nonce and capability checks, while not necessarily a direct risk given the zero attack surface, means that if any entry points were to be introduced in future versions, they might be unprotected. Overall, the plugin is well-secured based on current data, but vigilance regarding the bundled library and potential future additions to its attack surface is warranted.

Key Concerns

  • Bundled outdated library: TinyMCE v1.0.0
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Comment Form with TinyMCE Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Comment Form with TinyMCE Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE1.0.0
Attack Surface

Comment Form with TinyMCE Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filtercomment_form_defaultscomment-form-with-tinymce.php:27
Maintenance & Trust

Comment Form with TinyMCE Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedUnknown
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Comment Form with TinyMCE Developer Profile

Shail Mehta

11 plugins · 1K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Comment Form with TinyMCE

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wp-editor-container
FAQ

Frequently Asked Questions about Comment Form with TinyMCE