
Kindeditor For WordPress Security & Risk Analysis
wordpress.org/plugins/kindeditor-for-wordpressKindeditor for wordpress
Is Kindeditor For WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Kindeditor For WordPress has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'kindeditor-for-wordpress' plugin version 1.4.3 presents a mixed security profile. On the positive side, the static analysis shows a very limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or proper authorization checks. Furthermore, all SQL queries are confirmed to use prepared statements, and there are no critical or high-severity taint flows detected. The plugin also demonstrates a recent focus on security, with no currently unpatched CVEs and a single medium vulnerability from 2014 indicating historical but not persistent issues.
However, significant concerns arise from the output escaping. The analysis reveals that 100% of the 15 identified output points are not properly escaped. This is a critical weakness that could lead to Cross-Site Scripting (XSS) vulnerabilities, especially given that the plugin's historical vulnerability type is XSS. While the attack surface is small and the code is generally free of obvious dangerous functions and raw SQL, the lack of proper output escaping creates a substantial risk of data injection and malicious script execution. The single nonce check also suggests that not all potentially sensitive operations are adequately protected against replay attacks.
In conclusion, while 'kindeditor-for-wordpress' v1.4.3 benefits from a small attack surface and secure database practices, the pervasive issue of unescaped output poses a significant XSS risk. This, combined with the historical prevalence of XSS vulnerabilities in the plugin, necessitates careful attention. The plugin's strengths lie in its limited entry points and prepared SQL statements, but its weakness in output sanitation is a major security concern that could be exploited.
Key Concerns
- Unescaped output detected
- Medium severity vulnerability in history
- Limited nonce checks
Kindeditor For WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Kindeditor For WordPress < 1.4 - Reflected Cross-Site Scripting
Kindeditor For WordPress Release Timeline
Kindeditor For WordPress Code Analysis
Output Escaping
Data Flow Analysis
Kindeditor For WordPress Attack Surface
WordPress Hooks 10
Maintenance & Trust
Kindeditor For WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Kindeditor For WordPress Alternatives
Enlighter – Customizable Syntax Highlighter
enlighter
All-in-one Syntax Highlighting solution. Full Gutenberg and Classic Editor integration. Graphical theme customizer. Based on EnlighterJS.
ACE HTML Block
ace-html-block
Registers a raw html block which uses the ACE Editor. Features include syntax highligting, line numbers, indentation, and HTML validation.
HTML Block with Highlighting
html-block-with-highlighting
HTML Block with Highlighting is a WordPress plugin which adds a new HTML Block with syntax highlighting to the Gutenberg editor.
Melonpan Block – Code
melonpan-block-code
Block to display code, with highlighted syntax, which can be copied to the clipboard.
Light Code Block
light-code-block
The "Light Code Block" plugin is the simplest and lightest plugin for inserting and displaying code.
Kindeditor For WordPress Developer Profile
1 plugin · 500 total installs
How We Detect Kindeditor For WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kindeditor-for-wordpress/media-upload.js/wp-content/plugins/kindeditor-for-wordpress/kindeditor.js/wp-content/plugins/kindeditor-for-wordpress/lang/zh_CN.js/wp-content/plugins/kindeditor-for-wordpress/plugins.js/wp-content/plugins/kindeditor-for-wordpress/themes/default/default.css/wp-content/plugins/kindeditor-for-wordpress/plugins/code/prettify.js/wp-content/plugins/kindeditor-for-wordpress/plugins/code/prettify.css/wp-content/plugins/kindeditor-for-wordpress/media-upload.js/wp-content/plugins/kindeditor-for-wordpress/kindeditor.js/wp-content/plugins/kindeditor-for-wordpress/lang/zh_CN.js/wp-content/plugins/kindeditor-for-wordpress/plugins.js/wp-content/plugins/kindeditor-for-wordpress/plugins/code/prettify.js/wp-content/plugins/kindeditor-for-wordpress/media-upload.js?ver=/wp-content/plugins/kindeditor-for-wordpress/kindeditor.js?ver=/wp-content/plugins/kindeditor-for-wordpress/lang/zh_CN.js?ver=/wp-content/plugins/kindeditor-for-wordpress/plugins.js?ver=/wp-content/plugins/kindeditor-for-wordpress/plugins/code/prettify.js?ver=HTML / DOM Fingerprints
ke-containerke-icon-wpmoreke-icon-blockquote<![CDATA[//]]>data-editor-ideditoroptionsKindEditorprettyPrint