
Post Editor Buttons Security & Risk Analysis
wordpress.org/plugins/post-editor-buttonsThis plugin allows you add your own buttons to the post editor's toolbar.
Is Post Editor Buttons Safe to Use in 2026?
Generally Safe
Score 85/100Post Editor Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-editor-buttons" v1.7 plugin exhibits a generally strong security posture based on the provided static analysis. A significant strength is the complete absence of known CVEs and the fact that all SQL queries utilize prepared statements, demonstrating good database interaction practices. Furthermore, the plugin has no external HTTP requests or file operations, minimizing potential attack vectors. The zero entry points without authentication checks also suggest a thoughtful approach to protecting its functionality.
However, a critical concern arises from the complete lack of output escaping. With 12 total outputs analyzed and 0% properly escaped, this represents a significant vulnerability to Cross-Site Scripting (XSS) attacks. Attackers could potentially inject malicious scripts through the plugin's output, impacting users who interact with these elements. Additionally, the absence of nonce checks and capability checks on any potential entry points, though the static analysis reports zero entry points, is a missed opportunity for robust security even in limited scenarios. The vulnerability history being completely clean is positive, but it doesn't mitigate the identified output escaping issue.
In conclusion, while the plugin avoids common pitfalls like unpatched vulnerabilities and insecure SQL practices, the critical deficiency in output escaping leaves it exposed to XSS. Addressing this oversight is paramount for improving the plugin's overall security. The lack of any recorded vulnerabilities in its history is commendable, but the static analysis clearly highlights a significant and addressable risk.
Key Concerns
- All outputs are unescaped
- No nonce checks found
- No capability checks found
Post Editor Buttons Security Vulnerabilities
Post Editor Buttons Code Analysis
Output Escaping
Post Editor Buttons Attack Surface
WordPress Hooks 4
Maintenance & Trust
Post Editor Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Post Editor Buttons Alternatives
Post Editor Buttons Fork
post-editor-buttons-fork
This plugin allows you add your own buttons to the post editor's TEXT mode toolbar.
AddQuicktag
addquicktag
This plugin makes it easy to add Quicktags to the html - and visual-editor.
XHE Quicktags
xhe-quicktags
This plugin makes it easy to add Quicktags to the html - and visual-editor.
AddToAny Share Buttons
add-to-any
Share buttons for WordPress including the AddToAny button, Facebook, Bluesky, Mastodon, WhatsApp, Pinterest, Reddit, many more, and follow icons too.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Post Editor Buttons Developer Profile
4 plugins · 190 total installs
How We Detect Post Editor Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-editor-buttons/js.phpHTML / DOM Fingerprints
wrapform-tablebutton-primaryname="peb_caption[]"name="peb_before[]"name="peb_after[]"id="row