
Mentionable Security & Risk Analysis
wordpress.org/plugins/mentionableMention WordPress content with inline autocomplete inside tinyMCE.
Is Mentionable Safe to Use in 2026?
Generally Safe
Score 85/100Mentionable has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mentionable" plugin v0.4.3 exhibits a generally strong security posture based on the provided static analysis. It has a very limited attack surface, with only one AJAX handler, and crucially, this entry point appears to have authentication checks. The absence of SQL injection vulnerabilities, the use of prepared statements for all queries, and the presence of nonce and capability checks are all positive indicators. There are also no recorded vulnerabilities in its history, suggesting a history of stable and secure development.
However, there are areas for improvement. The output escaping is only properly handled for 63% of outputs, leaving a potential for cross-site scripting (XSS) vulnerabilities. While taint analysis shows no issues, this may be due to the limited scope of analysis or the absence of complex data flows. The presence of file operations without further context is also a minor concern, as these can sometimes be vectors for insecure operations if not handled carefully.
Overall, the plugin appears to be relatively secure due to its small attack surface, proper authentication, and lack of historical vulnerabilities. The primary concern lies in the incomplete output escaping, which warrants attention to prevent potential XSS flaws.
Key Concerns
- Incomplete output escaping
Mentionable Security Vulnerabilities
Mentionable Code Analysis
Output Escaping
Mentionable Attack Surface
AJAX Handlers 1
WordPress Hooks 13
Maintenance & Trust
Mentionable Maintenance & Trust
Maintenance Signals
Community Trust
Mentionable Alternatives
WP Super Edit
wp-super-edit
Get control of the WordPress wysiwyg visual editor and add some functionality with more buttons and custom TinyMCE plugins.
EditorFontsize
wp-editor-fontsize
Allows you to change a font size in a visual editor
GUI – Visual Editor
galau-ui-visual-editor
This plugin for edit your posts on the front-end of your site without going to wp-admin edit page, this work using tinymce inline technology.
NextGEN TinyMce Description
nextgen-tinymce-description
NextGEN TinyMce Description add native tinymce to nextgen gallery picture description.
Force Featured Image
force-featured-image
Ever wanted to force a user to publish a post with a featured image of a certain dimension? Search no more.
Mentionable Developer Profile
5 plugins · 710 total installs
How We Detect Mentionable
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mentionable/css/mentionable-style.css/wp-content/plugins/mentionable/css/mentionable-tmce-style.css/wp-content/plugins/mentionable/js/mentionable-tmce.js/wp-content/plugins/mentionable/js/mentionable-tmce.jsmentionable_css?ver=0.4.0HTML / DOM Fingerprints
data-mentionable-optionsmentionable