Disable WYSIWYG Security & Risk Analysis

wordpress.org/plugins/disable-wysiwyg

Disable TinyMCE Visual Editor (WYSIWYG editor) totally completely permanently forever

40 active installs v1.0.9 PHP + WP 1.5+ Updated Aug 11, 2021
adminadministrationcontentcontentsexcerpt
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Disable WYSIWYG Safe to Use in 2026?

Generally Safe

Score 85/100

Disable WYSIWYG has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "disable-wysiwyg" v1.0.9 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, unescaped output, file operations, external HTTP requests, and a clean taint analysis report are all positive indicators. Furthermore, the plugin has no recorded vulnerabilities, suggesting a history of stable and secure development. The total attack surface is zero, meaning there are no direct entry points that could be exploited without authentication, which is a significant strength.

However, the complete lack of nonces and capability checks across all potential entry points (even though there are none currently) is a notable concern. While the current lack of an attack surface mitigates immediate risk, it means that if the plugin were to be extended or modified in the future to include such points, it would inherently lack these fundamental security controls. This could lead to vulnerabilities if new features are added without proper security considerations. Overall, the plugin appears very secure in its current state due to its limited functionality and lack of exploitable code, but it has potential weaknesses that could be exposed by future development.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Disable WYSIWYG Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Disable WYSIWYG Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Disable WYSIWYG Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filteruser_can_richeditdisable-wysiwyg.php:29
Maintenance & Trust

Disable WYSIWYG Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedAug 11, 2021
PHP min version
Downloads6K

Community Trust

Rating92/100
Number of ratings5
Active installs40
Developer Profile

Disable WYSIWYG Developer Profile

Sparanoid

8 plugins · 4K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable WYSIWYG

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Disable WYSIWYG