MRW Simplified Editor Security & Risk Analysis

wordpress.org/plugins/mrw-web-design-simple-tinymce

Focus editors on making great content and letting their themes make it beautiful by removing block editor features.

100 active installs v2.14.0 PHP 5.6.20+ WP 6.5+ Updated Nov 18, 2025
block-editorblockseditoreditor-stylesgutenberg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MRW Simplified Editor Safe to Use in 2026?

Generally Safe

Score 100/100

MRW Simplified Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "mrw-web-design-simple-tinymce" plugin, version 2.14.0, presents an excellent security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries, file operations, or external HTTP requests is a significant strength. Furthermore, the complete lack of observed unsanitized taint flows and the 100% adherence to prepared statements for SQL and output escaping demonstrate robust development practices. The plugin also shows no recorded vulnerability history, suggesting a commitment to security or a lack of past exposure.

However, a notable concern arises from the complete absence of nonce checks and capability checks. While the attack surface is currently zero, any future additions or modifications to the plugin that introduce AJAX handlers, REST API routes, or shortcodes without these fundamental security measures would immediately create significant vulnerabilities. The bundled TinyMCE library, while not explicitly flagged as outdated, is an external component that could potentially harbor vulnerabilities if not kept up-to-date. The lack of any identified entry points is a positive sign, but it could also indicate a very limited functionality which might change in future versions.

In conclusion, the plugin exhibits strong internal code hygiene and a clean vulnerability history. The primary area for improvement and ongoing vigilance lies in implementing proper authentication and authorization checks (nonces and capabilities) for any future features that expose an attack surface. The bundled library's maintenance should also be considered.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Bundled outdated library (TinyMCE)
Vulnerabilities
None known

MRW Simplified Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MRW Simplified Editor Release Timeline

v2.14.0Current
v2.13.0
v2.12.1
v2.12.0
v2.11.1
v2.11.0
v2.10.0
v2.9.0
v2.8.0
v2.7.0
v2.6.1
v2.6.0
v2.5.0
v2.4.0
v2.3.0
v2.2.0
v2.1.0
v2.0.2
v2.0.1
v2.0.0
Code Analysis
Analyzed Mar 16, 2026

MRW Simplified Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE2.14.0
Attack Surface

MRW Simplified Editor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionafter_setup_themeinc\block-editor.php:2
actionplugins_loadedinc\block-editor.php:99
filtermrw_hidden_site_blocksinc\block-editor.php:247
filtermrw_hidden_query_blocksinc\block-editor.php:248
actionjetpack_register_gutenberg_extensionsinc\block-editor.php:331
filterblock_editor_settings_allinc\block-editor.php:465
actionenqueue_block_editor_assetsinc\block-editor.php:627
actionenqueue_block_assetsinc\block-editor.php:682
actionadmin_body_classinc\block-editor.php:694
filtermce_buttonsinc\classic-editor.php:4
filtermce_buttons_2inc\classic-editor.php:48
filtertiny_mce_before_initinc\classic-editor.php:50
Maintenance & Trust

MRW Simplified Editor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 18, 2025
PHP min version5.6.20
Downloads21K

Community Trust

Rating100/100
Number of ratings4
Active installs100
Developer Profile

MRW Simplified Editor Developer Profile

mrwweb

7 plugins · 8K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MRW Simplified Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mrw-web-design-simple-tinymce/inc/classic-editor.php/wp-content/plugins/mrw-web-design-simple-tinymce/inc/block-editor.php

HTML / DOM Fingerprints

HTML Comments
See if the Block Editor Colors plugin is activated. In that case, let it do its thingSee https://wordpress.org/plugins/block-editor-colors/mrw_block_editor_hide_color_palette filterSee https://developer.wordpress.org/block-editor/developers/themes/theme-support/#disabling-custom-colors-in-block-color-palettes+16 more
JS Globals
hidden_block_editor_settings
FAQ

Frequently Asked Questions about MRW Simplified Editor