Term Description: Rich Text Editor (Powered by TinyMCE) for WooCommerce Security & Risk Analysis

wordpress.org/plugins/rich-text-editor-tinymce-for-woocommerce

You can easily add the TinyMCE (WYSIWYG) editor to WooCommerce product categories and tags "description" for better formatting options.

600 active installs v1.2.0 PHP 7.4+ WP 6.2+ Updated Nov 19, 2025
categoryeditortinymcewoocommercewysiwyg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Term Description: Rich Text Editor (Powered by TinyMCE) for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Term Description: Rich Text Editor (Powered by TinyMCE) for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin "rich-text-editor-tinymce-for-woocommerce" v1.2.0 exhibits a generally strong security posture based on the provided static analysis. The absence of identified dangerous functions, SQL queries not using prepared statements, and properly escaped output are positive indicators. Furthermore, the plugin has no recorded vulnerabilities, which suggests a history of responsible development and maintenance. The lack of identified external HTTP requests, file operations, and a zero attack surface across AJAX handlers, REST API routes, shortcodes, and cron events are excellent security practices.

However, a significant concern arises from the complete absence of nonce checks and capability checks. While the current analysis shows no direct entry points without authentication, this lack of checks creates a potential blind spot. If any functionality were to be added or unintentionally exposed in the future, it could be vulnerable to CSRF attacks or privilege escalation if not properly secured with these checks. The bundled Freemius and TinyMCE libraries, while not explicitly flagged as outdated in this analysis, should always be monitored for security updates as they are common targets for attackers.

In conclusion, the plugin demonstrates good adherence to secure coding practices in its current state, particularly in data handling and preventing common web vulnerabilities. The absence of known vulnerabilities further bolsters confidence. The primary area for improvement and a potential risk lies in the complete omission of nonce and capability checks, which is a fundamental security mechanism in WordPress that should be implemented to safeguard against future threats.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Bundled library Freemius v1.0 potentially outdated
  • Bundled library TinyMCE v1.0 potentially outdated
Vulnerabilities
None known

Term Description: Rich Text Editor (Powered by TinyMCE) for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Term Description: Rich Text Editor (Powered by TinyMCE) for WooCommerce Release Timeline

v1.2.0Current
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Term Description: Rich Text Editor (Powered by TinyMCE) for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

Freemius1.0TinyMCE1.0

Output Escaping

100% escaped4 total outputs
Attack Surface

Term Description: Rich Text Editor (Powered by TinyMCE) for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterplugin_row_metaincludes\Base.php:8
actioncurrent_screenincludes\TinyMCE.php:25
filterpre_insert_termincludes\TinyMCE.php:28
actionadmin_enqueue_scriptsincludes\TinyMCE.php:29
actionprint_default_editor_scriptsincludes\TinyMCE.php:32
actionafter_wp_tiny_mceincludes\TinyMCE.php:33
Maintenance & Trust

Term Description: Rich Text Editor (Powered by TinyMCE) for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 19, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs600
Developer Profile

Term Description: Rich Text Editor (Powered by TinyMCE) for WooCommerce Developer Profile

hulkplugins

4 plugins · 840 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Term Description: Rich Text Editor (Powered by TinyMCE) for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rich-text-editor-tinymce-for-woocommerce/build/admin/tags/index.css/wp-content/plugins/rich-text-editor-tinymce-for-woocommerce/build/admin/tags/index.js
Script Paths
/wp-content/plugins/rich-text-editor-tinymce-for-woocommerce/build/admin/tags/index.js
Version Parameters
rich-text-editor-tinymce-for-woocommerce/build/admin/tags/index.css?ver=rich-text-editor-tinymce-for-woocommerce/build/admin/tags/index.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-editor-id="tag-description"data-editor-id="description"
JS Globals
hulk_woo_tmcecd_settings
FAQ

Frequently Asked Questions about Term Description: Rich Text Editor (Powered by TinyMCE) for WooCommerce