Movable Content Editor Security & Risk Analysis

wordpress.org/plugins/movable-content-editor

This plugin makes the main content editor movable with drag and drop.

10 active installs v0.1.8 PHP + WP 3.8.1+ Updated Aug 28, 2014
bettercontent-editoreditingmovablewysiwyg
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Movable Content Editor Safe to Use in 2026?

Generally Safe

Score 85/100

Movable Content Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "movable-content-editor" plugin v0.1.8 exhibits a strong security posture based on the static analysis. The absence of any identified entry points, dangerous functions, file operations, external requests, and raw SQL queries is highly commendable. Furthermore, the absence of any recorded vulnerabilities or CVEs in its history suggests a history of secure development or a lack of prior scrutiny. This plugin appears to be well-defended against common web attack vectors.

However, there are notable areas of concern that warrant attention. The most significant is the extremely low percentage of properly escaped output (14%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or content processed by the plugin may not be adequately neutralized before being rendered in the browser. Additionally, the complete lack of nonce checks and capability checks across all identified entry points (though there are none explicitly listed) implies that if any entry points were to be discovered or introduced in future versions, they would likely be unprotected, making them susceptible to unauthorized actions. While the current lack of identified vulnerabilities is positive, the output escaping deficiency presents a clear and present danger that should be addressed promptly.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Movable Content Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Movable Content Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

14% escaped7 total outputs
Attack Surface

Movable Content Editor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitmovable-content-editor.php:49
actioncurrent_screenmovable-content-editor.php:51
actionadmin_menumovable-content-editor.php:55
actionadmin_initmovable-content-editor.php:56
actionadd_meta_boxesmovable-content-editor.php:68
actionadmin_enqueue_scriptsmovable-content-editor.php:71
actionadmin_enqueue_scriptsmovable-content-editor.php:72
actionadmin_enqueue_scriptsmovable-content-editor.php:76
actionadmin_enqueue_scriptsmovable-content-editor.php:77
Maintenance & Trust

Movable Content Editor Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedAug 28, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Movable Content Editor Developer Profile

Peter Elmered

3 plugins · 320 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Movable Content Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/movable-content-editor/assets/admin.css/wp-content/plugins/movable-content-editor/assets/admin-options.css/wp-content/plugins/movable-content-editor/assets/admin-options.js/wp-content/plugins/movable-content-editor/assets/admin.js
Script Paths
/wp-content/plugins/movable-content-editor/assets/admin.js/wp-content/plugins/movable-content-editor/assets/admin-options.js
Version Parameters
movable-content-editor/assets/admin.css?ver=movable-content-editor/assets/admin-options.css?ver=movable-content-editor/assets/admin-options.js?ver=movable-content-editor/assets/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
movableContentEditormovableContentOptions
FAQ

Frequently Asked Questions about Movable Content Editor