
Disable WYSIWYG Security & Risk Analysis
wordpress.org/plugins/disable-wysiwygDisable TinyMCE Visual Editor (WYSIWYG editor) totally completely permanently forever
Is Disable WYSIWYG Safe to Use in 2026?
Generally Safe
Score 85/100Disable WYSIWYG has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "disable-wysiwyg" v1.0.9 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, external HTTP requests, and a clean taint analysis report are all positive indicators. Furthermore, the plugin has no recorded vulnerabilities, suggesting a history of stable and secure development. The total attack surface is zero, meaning there are no direct entry points that could be exploited without authentication, which is a significant strength.
However, the complete lack of nonces and capability checks across all potential entry points (even though there are none currently) is a notable concern. While the current lack of an attack surface mitigates immediate risk, it means that if the plugin were to be extended or modified in the future to include such points, it would inherently lack these fundamental security controls. This could lead to vulnerabilities if new features are added without proper security considerations. Overall, the plugin appears very secure in its current state due to its limited functionality and lack of exploitable code, but it has potential weaknesses that could be exposed by future development.
Key Concerns
- Missing nonce checks
- Missing capability checks
Disable WYSIWYG Security Vulnerabilities
Disable WYSIWYG Code Analysis
Disable WYSIWYG Attack Surface
WordPress Hooks 1
Maintenance & Trust
Disable WYSIWYG Maintenance & Trust
Maintenance Signals
Community Trust
Disable WYSIWYG Alternatives
Relative URL
relative-url
Relative URL applies wp_make_link_relative function to links to convert them to relative URLs.
Quotmarks Replacer
quotmarks-replacer
Quotmarks Replacer disables wptexturize function that keeps all quotation marks and suspension points in half-width form.
Manage User Roles
manage-user-roles
A flexible plugin to control content visibility for non-administrator users with advanced, role-based rules.
Easy Table of Contents
easy-table-of-contents
Adds a user friendly and fully automatic way to create and display a table of contents generated from the page content.
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
Disable WYSIWYG Developer Profile
8 plugins · 4K total installs
How We Detect Disable WYSIWYG
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.