Revision Manager TMC Security & Risk Analysis

wordpress.org/plugins/revision-manager-tmc

Clone your post, page or custom post type to a draft. Draft up revisions of live, published content. Accept posts. It works with ACF...

1K active installs v2.8.22 PHP 7.1+ WP 6.0.0+ Updated Sep 10, 2025
clone-postrevisionrevision-controlrevision-managerrevisionary
76
B · Generally Safe
CVEs total2
Unpatched1
Last CVEJan 28, 2026
Download
Safety Verdict

Is Revision Manager TMC Safe to Use in 2026?

Mostly Safe

Score 76/100

Revision Manager TMC is generally safe to use. 2 past CVEs were resolved. Keep it updated.

2 known CVEs 1 unpatched Last CVE: Jan 28, 2026Updated 6mo ago
Risk Assessment

The "revision-manager-tmc" plugin v2.8.22 exhibits a mixed security posture. On the positive side, the static analysis reveals a robust implementation of security best practices. There are no unprotected entry points identified across AJAX handlers, REST API routes, shortcodes, or cron events. SQL queries are exclusively handled with prepared statements, and a high percentage of output is properly escaped, mitigating common injection vulnerabilities. The presence of nonce and capability checks further strengthens its defenses. However, the plugin's vulnerability history is a significant concern. With two known CVEs, one of which remains unpatched, this indicates a pattern of previously discovered security flaws. The nature of these past vulnerabilities (CSRF, Missing Authorization) suggests potential weaknesses in how user actions and permissions are handled, even if current static analysis doesn't immediately flag them. The unpatched CVE, in particular, represents a direct and actionable risk to sites using this plugin.

While the current version's code analysis suggests good adherence to secure coding principles, the historical pattern of vulnerabilities cannot be ignored. The unpatched CVE is the most critical risk. The bundled TinyMCE library, while not flagged as a specific issue here, is a common vector for vulnerabilities in other contexts and should be monitored for updates, though no direct deduction is made based solely on its presence. The plugin demonstrates strengths in its secure entry point management and query handling but weaknesses are highlighted by its past security incidents and the presence of an unpatched vulnerability.

Key Concerns

  • Unpatched known CVEs
  • Bundled library (TinyMCE)
Vulnerabilities
2

Revision Manager TMC Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-25411medium · 4.3Cross-Site Request Forgery (CSRF)

Revision Manager TMC <= 2.8.22 - Cross-Site Request Forgery

Jan 28, 2026Unpatched
CVE-2024-7622medium · 4.3Missing Authorization

Revision Manager TMC <= 2.8.19 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending

Sep 6, 2024 Patched in 2.8.20 (1d)
Code Analysis
Analyzed Mar 16, 2026

Revision Manager TMC Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
28 escaped
Nonce Checks
3
Capability Checks
16
File Operations
1
External Requests
2
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

90% escaped31 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
_a_manualRevisionAcceptance (src\Components\Revisions.php:622)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Revision Manager TMC Attack Surface

Entry Points4
Unprotected0

REST API Routes 4

POST/wp-json/rm_tmc/v1/options/savesrc\Components\AdminPage.php:56
POST/wp-json/rm_tmc/v1/options/loadsrc\Components\AdminPage.php:64
POST/wp-json/rm_tmc/v1jetplugs/a/(?P<code>[\w-]+)src\Components\JetPlugs.php:25
POST/wp-json/rm_tmc/v1jetplugs/d/(?P<code>[\w-]+)src\Components\JetPlugs.php:33
WordPress Hooks 28
actionacf/render_fieldsrc\Components\AcfDifferences.php:32
actionacf/input/admin_headsrc\Components\AcfDifferences.php:33
actionacf/input/admin_enqueue_scriptssrc\Components\AcfDifferences.php:34
filteracf/prepare_fieldsrc\Components\AcfDifferences.php:40
actionadmin_menusrc\Components\AdminPage.php:22
actionadmin_enqueue_scriptssrc\Components\AdminPage.php:35
actionrest_api_initsrc\Components\AdminPage.php:54
filterplugin_action_links_revision-manager-tmc/revision-manager-tmc.phpsrc\Components\AdminPage.php:74
actionwp_dashboard_setupsrc\Components\DashboardWidget.php:25
actionrest_api_initsrc\Components\JetPlugs.php:23
actionadmin_bar_menusrc\Components\Revisions.php:41
actionenqueue_block_editor_assetssrc\Components\Revisions.php:43
actionwp_enqueue_editorsrc\Components\Revisions.php:44
actionwp_enqueue_scriptssrc\Components\Revisions.php:45
actionelementor/editor/before_enqueue_scriptssrc\Components\Revisions.php:46
actionpost_submitbox_misc_actionssrc\Components\Revisions.php:48
actionedit_form_before_permalinksrc\Components\Revisions.php:49
actionedit_form_after_editorsrc\Components\Revisions.php:50
actionadd_meta_boxessrc\Components\Revisions.php:51
actioninitsrc\Components\Revisions.php:55
actionsave_postsrc\Components\Revisions.php:59
actionpending_to_publishsrc\Components\Revisions.php:64
actiondraft_to_publishsrc\Components\Revisions.php:65
actionfuture_to_publishsrc\Components\Revisions.php:66
actionsave_postsrc\Components\Revisions.php:68
filterpost_row_actionssrc\Components\Revisions.php:76
filterpage_row_actionssrc\Components\Revisions.php:77
filterdisplay_post_statessrc\Components\Revisions.php:78
Maintenance & Trust

Revision Manager TMC Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 10, 2025
PHP min version7.1
Downloads56K

Community Trust

Rating98/100
Number of ratings10
Active installs1K
Developer Profile

Revision Manager TMC Developer Profile

themastercut

3 plugins · 1K total installs

87
trust score
Avg Security Score
82/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Revision Manager TMC

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/revision-manager-tmc/assets/js/AdminPageOptions/dist/revision-manager-tmc.umd.min.js/wp-content/plugins/revision-manager-tmc/assets/js/AdminPageOptions/dist/revision-manager-tmc.css
Script Paths
/wp-content/plugins/revision-manager-tmc/assets/js/AdminPageOptions/dist/revision-manager-tmc.umd.min.js
Version Parameters
revision-manager-tmc.umd.min.js?ver=revision-manager-tmc.css?ver=

HTML / DOM Fingerprints

CSS Classes
rm_tmc_settings
Data Attributes
data-prefix="rm_tmc"data-ajax_urldata-rest_api_save_options_urldata-rest_api_load_options_urldata-jetplugs_a_urldata-jetplugs_d_url+1 more
JS Globals
rm_tmc_settingsrm_tmc_fieldsData
REST Endpoints
/wp-json/rm_tmc/v1/options/save/wp-json/rm_tmc/v1/options/load/wp-json/rm_tmc/v1/jetplugs/a/wp-json/rm_tmc/v1/jetplugs/d
FAQ

Frequently Asked Questions about Revision Manager TMC