Empty Paragraph for TinyMCE Editor Security & Risk Analysis

wordpress.org/plugins/empty-paragraph-for-tinymce-editor

Adds an editor button that puts in an empty paragraph which won't get deleted when you save.

60 active installs v0.9.3 PHP + WP 3.0.4+ Updated Feb 17, 2012
linebreaknbspptinymcewhitespace
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Empty Paragraph for TinyMCE Editor Safe to Use in 2026?

Generally Safe

Score 85/100

Empty Paragraph for TinyMCE Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "empty-paragraph-for-tinymce-editor" plugin version 0.9.3 exhibits a strong security posture based on the provided static analysis results. The absence of any identified attack surface points, dangerous functions, or file operations is a significant strength. Furthermore, the complete reliance on prepared statements for SQL queries and proper output escaping demonstrates good coding practices regarding data handling and prevention of common vulnerabilities like SQL injection and XSS.

The vulnerability history shows no known CVEs, which is excellent and indicates a history of stable, secure development. The lack of any identified taint flows with unsanitized paths reinforces the positive assessment of the code's security. The complete absence of external HTTP requests also removes a potential avenue for various attacks.

While the lack of explicit capability checks and nonce checks on potential entry points could be a concern in plugins with larger attack surfaces, for this plugin's apparent minimal functionality and zero identified entry points, it doesn't present an immediate, evidence-backed risk. The plugin appears to be securely developed with minimal exposure to common web vulnerabilities.

Vulnerabilities
None known

Empty Paragraph for TinyMCE Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Empty Paragraph for TinyMCE Editor Release Timeline

v0.9.3Current
v0.9.2
v0.9.1
v0.9.0
Code Analysis
Analyzed Mar 16, 2026

Empty Paragraph for TinyMCE Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Empty Paragraph for TinyMCE Editor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filtermce_external_pluginsindex.php:11
filtermce_buttonsindex.php:12
Maintenance & Trust

Empty Paragraph for TinyMCE Editor Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedFeb 17, 2012
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

Empty Paragraph for TinyMCE Editor Developer Profile

kb_unhammer

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Empty Paragraph for TinyMCE Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/empty-paragraph-for-tinymce-editor/editor_plugin.js
Script Paths
/wp-content/plugins/empty-paragraph-for-tinymce-editor/editor_plugin.js
Version Parameters
empty-paragraph-for-tinymce-editor/editor_plugin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Empty Paragraph for TinyMCE Editor