
Foliopress WYSIWYG Security & Risk Analysis
wordpress.org/plugins/foliopress-wysiwygFoliopress WYSIWYG is the editor you were always hoping for, every time you installed a new content management system.
Is Foliopress WYSIWYG Safe to Use in 2026?
Generally Safe
Score 90/100Foliopress WYSIWYG has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The foliopress-wysiwyg plugin v2.6.18 presents a mixed security posture. While it demonstrates some good practices like using prepared statements for all SQL queries and a moderate number of nonce and capability checks, significant concerns arise from its attack surface and vulnerability history. One AJAX handler is not protected by authentication checks, creating an immediate potential entry point for unauthorized actions. Furthermore, the taint analysis indicates a concerning number of flows with unsanitized paths, suggesting potential vulnerabilities even if no critical or high severity issues were immediately flagged in this scan. The plugin's history of three known medium-severity vulnerabilities, including Cross-Site Request Forgery and Cross-site Scripting, and notably, one unpatched vulnerability, strongly indicates a recurring pattern of insecure coding practices that have historically exposed users to risk. The prevalence of Cross-site Scripting vulnerabilities in the past is particularly worrying given the static analysis showing only 39% of outputs are properly escaped.
Key Concerns
- Unprotected AJAX handler
- High number of unsanitized paths in taint flows
- Unpatched CVE
- Vulnerability history shows common XSS and CSRF
- Low percentage of properly escaped outputs
- Use of dangerous function (shell_exec)
Foliopress WYSIWYG Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Foliopress WYSIWYG <= 2.6.18 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Foliopress WYSIWYG < 2.6.16 - Cross-Site Scripting
Foliopress WYSIWYG < 2.6.8.5 - Cross-Site Scripting
Foliopress WYSIWYG Release Timeline
Foliopress WYSIWYG Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Foliopress WYSIWYG Attack Surface
AJAX Handlers 2
WordPress Hooks 32
Maintenance & Trust
Foliopress WYSIWYG Maintenance & Trust
Maintenance Signals
Community Trust
Foliopress WYSIWYG Alternatives
ThumbPress – Image Management Suite for Performance and Optimization
image-sizes
Disable Thumbnails, Regenerate Thumbnails, Compress Images, Convert to WebP, Find Unused and Large Images, Edit Images, and more with ThumbPress.
Thumbnail Upscale
thumbnail-upscale
Enables upscaling of thumbnails for small media attachments
Image Pro – Image resizing and media management done right
image-pro-wordpress-image-media-management-and-resizing-done-right
Upload, resize, add, change images instantly. Manage your media collection with ease and use it for any post or page. A new way of managing content!
Shutterstock
shutterstock
Insert Shutterstock's royalty-free content directly from the WordPress editor
Tinymce Thumbnail Gallery
tinymce-thumbnail-gallery
This plugin is a simple image gallery built into TinyMCE. Add media to your gallery easily and display thumbnails in a clean fashion.
Foliopress WYSIWYG Developer Profile
19 plugins · 48K total installs
How We Detect Foliopress WYSIWYG
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/foliopress-wysiwyg/foliopress-wysiwyg.php/wp-content/plugins/foliopress-wysiwyg/fckeditor/editor/dialog/internal-link.php/wp-content/plugins/foliopress-wysiwyg/fckeditor/editor/skins/office2003/dialog.css/wp-content/plugins/foliopress-wysiwyg/fckeditor/fckconfig.js/wp-content/plugins/foliopress-wysiwyg/fckeditor/fckeditor.js/wp-content/plugins/foliopress-wysiwyg/fckeditor/fckstyles.xml/wp-content/plugins/foliopress-wysiwyg/fckeditor/editor/plugins/wordpress/fck_wordpress.js/wp-content/plugins/foliopress-wysiwyg/fckeditor/editor/plugins/table/fck_table.js+10 more/wp-content/plugins/foliopress-wysiwyg/fckeditor/fckeditor.js/wp-content/plugins/foliopress-wysiwyg/fckeditor/editor/plugins/wordpress/fck_wordpress.js/wp-content/plugins/foliopress-wysiwyg/js/tinymce_override.js/wp-content/plugins/foliopress-wysiwyg/js/fv_tinymce.jsfoliopress-wysiwyg/style.css?ver=foliopress-wysiwyg/foliopress-wysiwyg.php?ver=foliopress-wysiwyg/js/fv_tinymce.js?ver=HTML / DOM Fingerprints
fp-wysiwyg-editor<!-- BEGIN: FOLIOpress WYSIWYG --><!-- END: FOLIOpress WYSIWYG -->data-fv-iddata-fv-langdata-fv-toolbardata-fv-dialogdata-fv-skinFCKEDITORFOLIOpress_WYSIWYG/wp-json/foliopress-wysiwyg/v1/settings[foliopress_wysiwyg]