
Revision Manager TMC Security & Risk Analysis
wordpress.org/plugins/revision-manager-tmcClone your post, page or custom post type to a draft. Draft up revisions of live, published content. Accept posts. It works with ACF...
Is Revision Manager TMC Safe to Use in 2026?
Mostly Safe
Score 76/100Revision Manager TMC is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The "revision-manager-tmc" plugin v2.8.22 exhibits a mixed security posture. On the positive side, the static analysis reveals a robust implementation of security best practices. There are no unprotected entry points identified across AJAX handlers, REST API routes, shortcodes, or cron events. SQL queries are exclusively handled with prepared statements, and a high percentage of output is properly escaped, mitigating common injection vulnerabilities. The presence of nonce and capability checks further strengthens its defenses. However, the plugin's vulnerability history is a significant concern. With two known CVEs, one of which remains unpatched, this indicates a pattern of previously discovered security flaws. The nature of these past vulnerabilities (CSRF, Missing Authorization) suggests potential weaknesses in how user actions and permissions are handled, even if current static analysis doesn't immediately flag them. The unpatched CVE, in particular, represents a direct and actionable risk to sites using this plugin.
While the current version's code analysis suggests good adherence to secure coding principles, the historical pattern of vulnerabilities cannot be ignored. The unpatched CVE is the most critical risk. The bundled TinyMCE library, while not flagged as a specific issue here, is a common vector for vulnerabilities in other contexts and should be monitored for updates, though no direct deduction is made based solely on its presence. The plugin demonstrates strengths in its secure entry point management and query handling but weaknesses are highlighted by its past security incidents and the presence of an unpatched vulnerability.
Key Concerns
- Unpatched known CVEs
- Bundled library (TinyMCE)
Revision Manager TMC Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Revision Manager TMC <= 2.8.22 - Cross-Site Request Forgery
Revision Manager TMC <= 2.8.19 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending
Revision Manager TMC Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Revision Manager TMC Attack Surface
REST API Routes 4
WordPress Hooks 28
Maintenance & Trust
Revision Manager TMC Maintenance & Trust
Maintenance Signals
Community Trust
Revision Manager TMC Alternatives
WP Revisions Manager
wp-revisions-manager
WP Revisions Manager let you purge (delete) its revisions via AJAX. There is also a Bulk action in the post lists. You can also limit the number of re …
Revisions Control Ultimate
revisions-control-ultimate
Control WordPress post revisions and autosaves for better performance and optimization.
No Updates for Plugins under Revision Control
no-updates-for-plugins-under-svn
Prevents plugins from being updated by the WordPress updater if they are under Subversion revision control (or other systems).
Content Republish – Easily update and republish your content
content-republish
Content Republish allows you to easily clone your posts, update the content and schedule it for republication.
Duplicate Page and Post
duplicate-wp-page-post
Duplicate post, Duplicate page and Duplicate custom post or clone page and clone post.
Revision Manager TMC Developer Profile
3 plugins · 1K total installs
How We Detect Revision Manager TMC
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/revision-manager-tmc/assets/js/AdminPageOptions/dist/revision-manager-tmc.umd.min.js/wp-content/plugins/revision-manager-tmc/assets/js/AdminPageOptions/dist/revision-manager-tmc.css/wp-content/plugins/revision-manager-tmc/assets/js/AdminPageOptions/dist/revision-manager-tmc.umd.min.jsrevision-manager-tmc.umd.min.js?ver=revision-manager-tmc.css?ver=HTML / DOM Fingerprints
rm_tmc_settingsdata-prefix="rm_tmc"data-ajax_urldata-rest_api_save_options_urldata-rest_api_load_options_urldata-jetplugs_a_urldata-jetplugs_d_url+1 morerm_tmc_settingsrm_tmc_fieldsData/wp-json/rm_tmc/v1/options/save/wp-json/rm_tmc/v1/options/load/wp-json/rm_tmc/v1/jetplugs/a/wp-json/rm_tmc/v1/jetplugs/d