
Compact MCE Security & Risk Analysis
wordpress.org/plugins/compact-mceA simple plugin that re-organize your WordPress editor TinyMCE controls.
Is Compact MCE Safe to Use in 2026?
Generally Safe
Score 85/100Compact MCE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "compact-mce" v19.05 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. File operations and external HTTP requests are also absent, indicating good security practices in these areas. The lack of any recorded vulnerabilities, including CVEs, suggests a history of stable and secure development.
While the static analysis shows no immediate threats, the complete absence of nonces and capability checks across all entry points (even though there are none in this version) represents a potential concern. If the plugin were to introduce any new entry points in the future without implementing these security measures, it could become vulnerable to various attacks, such as Cross-Site Request Forgery (CSRF) or unauthorized actions. The bundling of TinyMCE also means that any vulnerabilities in TinyMCE itself could potentially affect this plugin, although no specific issues were flagged in the provided data.
In conclusion, "compact-mce" v19.05 appears to be a secure plugin with a clean history and excellent coding practices regarding SQL and output sanitization. The primary area of caution lies in the non-existent but crucial security checks like nonces and capability checks, which, if not addressed during future development, could pose a risk. However, given the current lack of entry points and vulnerability history, the overall risk is currently very low.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
- Bundled outdated library (TinyMCE)
Compact MCE Security Vulnerabilities
Compact MCE Code Analysis
Bundled Libraries
Compact MCE Attack Surface
WordPress Hooks 4
Maintenance & Trust
Compact MCE Maintenance & Trust
Maintenance Signals
Community Trust
Compact MCE Alternatives
TinyMCE Templates
tinymce-templates
TinyMCE Template plugin will enable to use HTML template on WordPress Visual Editor.
f(x) Editor
fx-editor
Power-up Your WordPress Visual Editor with Boxes, Buttons, Columns, and more...
TinyMCE VisualBlocks
tinymce-visualblocks
View VisualBlocks in WordPress Visual Editor.
tinyWYM Editor
tinywym-editor
Convert WordPress's WYSIWYG editor into a WYSIWYM editor. Add and edit any HTML tag and attribute from the visual editor.
Visual Editor Font Size
visual-editor-font-size
Allows you to change the font size of the visual editor
Compact MCE Developer Profile
3 plugins · 510 total installs
How We Detect Compact MCE
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/compact-mce/tinymce/codesample/plugin.min.js/wp-content/plugins/compact-mce/tinymce/contextmenu/plugin.min.js/wp-content/plugins/compact-mce/tinymce/searchreplace/plugin.min.js/wp-content/plugins/compact-mce/tinymce/table/plugin.min.js/wp-content/plugins/compact-mce/tinymce/visualblocks/plugin.min.js