
Custom Text Formats Security & Risk Analysis
wordpress.org/plugins/custom-text-formatsCustom Text Formats lets you add custom text formats to the Gutenberg Editor
Is Custom Text Formats Safe to Use in 2026?
Generally Safe
Score 92/100Custom Text Formats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "custom-text-formats" v1.1 exhibits a very strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events, along with zero unprotected entry points, significantly limits the potential attack surface. Furthermore, the code demonstrates excellent security practices, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The lack of any identified taint flows, critical or otherwise, also contributes to a positive security assessment. The plugin's vulnerability history is also clean, with no recorded CVEs, indicating a consistent track record of security. While the presence of file operations is noted, without further context on their nature, it's difficult to assign a specific risk. The plugin's strengths lie in its minimal attack surface and adherence to secure coding practices. The main concern, if any, would be the complete absence of nonce and capability checks, which might suggest a lack of built-in protection mechanisms for administrative actions if such actions were to exist, though the current analysis shows no such entry points.
Key Concerns
- No nonce checks found
- No capability checks found
Custom Text Formats Security Vulnerabilities
Custom Text Formats Code Analysis
Output Escaping
Custom Text Formats Attack Surface
WordPress Hooks 8
Maintenance & Trust
Custom Text Formats Maintenance & Trust
Maintenance Signals
Community Trust
Custom Text Formats Alternatives
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
Kirki Customizer Framework
kirki
The Ultimate Customizer Framework for WordPress Theme Developers
LoginPress | wp-login Custom Login Page Customizer
loginpress
LoginPress is a Custom Login Page Customizer plugin allows you to easily customize the layout of login, admin login, client login, register pages.
Customizer Export/Import
customizer-export-import
Easily export or import your WordPress customizer settings!
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
themeisle-companion
Add modules like share buttons, header & footer scripts, disable comments, reading progress bar, custom fonts, custom login page & more in one plugin.
Custom Text Formats Developer Profile
2 plugins · 4K total installs
How We Detect Custom Text Formats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-text-formats/css/admin-style.css/wp-content/plugins/custom-text-formats/js/admin_scripts.js/wp-content/plugins/custom-text-formats/css/codemirror.css/wp-content/plugins/custom-text-formats/css/dracula.css/wp-content/plugins/custom-text-formats/js/codemirror.js/wp-content/plugins/custom-text-formats/js/mode/xml/xml.js/wp-content/plugins/custom-text-formats/js/mode/javascript/javascript.js/wp-content/plugins/custom-text-formats/js/mode/css/css.js+1 more/wp-content/plugins/custom-text-formats/js/admin_scripts.js/wp-content/plugins/custom-text-formats/js/codemirror.js/wp-content/plugins/custom-text-formats/js/mode/xml/xml.js/wp-content/plugins/custom-text-formats/js/mode/javascript/javascript.js/wp-content/plugins/custom-text-formats/js/mode/css/css.js/wp-content/plugins/custom-text-formats/js/mode/htmlmixed/htmlmixed.jscustom-text-formats/css/admin-style.css?ver=custom-text-formats/js/admin_scripts.js?ver=custom-text-formats/css/codemirror.css?ver=custom-text-formats/css/dracula.css?ver=custom-text-formats/js/codemirror.js?ver=custom-text-formats/js/mode/xml/xml.js?ver=custom-text-formats/js/mode/javascript/javascript.js?ver=custom-text-formats/js/mode/css/css.js?ver=custom-text-formats/js/mode/htmlmixed/htmlmixed.js?ver=HTML / DOM Fingerprints
gctf_inputblockgctf_radiobtngctf_inputboxgctf_labelgctf_desccustom-dropdownselected-optionselected-icon+4 more<!-- Get Custom icons --><!-- end get custom icons --><!-- Loop custom Icons --><!--Loop dashicons -->data-valuedata-icontypeid="wrap_tag"id="classname"id="gctf_wrap"id="block"+5 moregctf_register_posttypegctf_load_formatsgctf_createEditorstyleFoldergctf_admin_initgctf_customAdmingctf_save_options+5 more