
More Buttons Security & Risk Analysis
wordpress.org/plugins/more-buttonsAdd More Useful Buttons to TinyMCE Editors. 在TinyMCE編輯器上增加更多實用的按鈕
Is More Buttons Safe to Use in 2026?
Generally Safe
Score 85/100More Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'more-buttons' plugin version 1.0.4 exhibits a strong security posture based on the provided static analysis results. There are no identified entry points into the plugin that are unprotected, meaning all potential interaction points like AJAX handlers, REST API routes, shortcodes, and cron events are either absent or secured. Furthermore, the code demonstrates excellent practices by not utilizing dangerous functions, all SQL queries are prepared, and all outputs are properly escaped. The absence of file operations, external HTTP requests, and the lack of critical signals in taint analysis further contribute to a secure coding profile.
The vulnerability history is also exceptionally clean, with no recorded CVEs of any severity. This indicates a history of secure development and maintenance, or that the plugin has not been a target for discovery of vulnerabilities. The lack of any common vulnerability types suggests a thorough approach to security from the developers. However, it's important to note that the complete absence of certain security checks, such as nonce checks and capability checks, is unusual for plugins that might otherwise have potential entry points. While the current analysis shows no unprotected entry points, the lack of these checks could become a concern if future updates introduce new functionalities without proper security controls.
In conclusion, 'more-buttons' v1.0.4 presents as a very secure plugin. Its static analysis reveals robust coding practices and a clean vulnerability history. The primary observation, while not a deduction of a current vulnerability, is the complete absence of nonce and capability checks, which, in the absence of any attack surface, is currently not a risk but a point to monitor for future development. Overall, this plugin appears to be a low-risk option.
Key Concerns
- No capability checks found
- No nonce checks found
More Buttons Security Vulnerabilities
More Buttons Code Analysis
More Buttons Attack Surface
WordPress Hooks 1
Maintenance & Trust
More Buttons Maintenance & Trust
Maintenance Signals
Community Trust
More Buttons Alternatives
Black Studio TinyMCE Widget
black-studio-tinymce-widget
The visual editor widget for WordPress.
AddQuicktag
addquicktag
This plugin makes it easy to add Quicktags to the html - and visual-editor.
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
post-and-page-builder
Post and Page Builder is a standalone plugin which adds functionality to the existing TinyMCE Editor.
TinyMCE Templates
tinymce-templates
TinyMCE Template plugin will enable to use HTML template on WordPress Visual Editor.
Visual Term Description Editor
visual-term-description-editor
Replaces the plain-text category and tag description editor with a visual editor.
More Buttons Developer Profile
24 plugins · 2K total installs
How We Detect More Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.