Link media from TinyMCE Security & Risk Analysis

wordpress.org/plugins/link-media-from-tinymce

This plugin allows you to create links to elements of the media in the Wysiwyg editor

200 active installs v1.0 PHP + WP 3+ Updated Apr 13, 2014
linkmediamedia-linkwysiwyg-link
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Link media from TinyMCE Safe to Use in 2026?

Generally Safe

Score 85/100

Link media from TinyMCE has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "link-media-from-tinymce" plugin, version 1.0, presents a strong initial security posture based on the provided static analysis. It exhibits zero known CVEs and no recorded vulnerabilities, suggesting a history of secure development or thorough prior auditing. Furthermore, the code demonstrates good practices with 100% of SQL queries using prepared statements and a complete absence of dangerous functions, file operations, or external HTTP requests. The attack surface is also remarkably clean, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct entry points for attackers to exploit.

However, a significant concern arises from the complete lack of capability checks and nonce checks. While the attack surface is currently zero, any future addition or a subtle misconfiguration could expose these components to unauthorized access or manipulation. The fact that 50% of outputs are not properly escaped, even with a small total number of outputs, represents a potential cross-site scripting (XSS) vulnerability if user-supplied data is ever rendered directly without sanitization. The absence of taint analysis flows is also noteworthy; while this implies no critical or high-severity unsanitized paths were detected in this analysis, it's important to remember that taint analysis is only as good as its coverage.

In conclusion, the plugin's current state is highly secure with no identified vulnerabilities. Its strengths lie in its minimal attack surface and secure handling of database operations. The primary weaknesses are the absence of capability and nonce checks, which could be exploited if the plugin's functionality expands or if its limited output escaping is mishandled. Given the lack of historical vulnerabilities and the minimal attack surface, the overall risk is low, but the missing security controls for potential future entry points warrant attention.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
  • Unescaped output detected
Vulnerabilities
None known

Link media from TinyMCE Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Link media from TinyMCE Release Timeline

v1.0Current
Code Analysis
Analyzed Mar 16, 2026

Link media from TinyMCE Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

Link media from TinyMCE Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterwp_link_query_argsdeefuse-link-media-in-wysiwyg.php:33
filterwp_link_querydeefuse-link-media-in-wysiwyg.php:34
actionadmin_menuincludes\settings.php:20
actionadmin_initincludes\settings.php:21
Maintenance & Trust

Link media from TinyMCE Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedApr 13, 2014
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

Link media from TinyMCE Developer Profile

Aurélien LWS

10 plugins · 78K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
222 days
View full developer profile
Detection Fingerprints

How We Detect Link media from TinyMCE

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Link media from TinyMCE