
SyntaxHighlighter TinyMCE Button Security & Risk Analysis
wordpress.org/plugins/syntaxhighlighter-tinymce-button"SyntaxHighlighter TinyMCE Button" provides buttons for Visual Editor and will help to type <pre> tag for SyntaxHighlighter.
Is SyntaxHighlighter TinyMCE Button Safe to Use in 2026?
Generally Safe
Score 85/100SyntaxHighlighter TinyMCE Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The syntaxhighlighter-tinymce-button v0.7.8.4 plugin demonstrates a strong security posture in several key areas. The absence of any known vulnerabilities, including historical ones, is a significant positive indicator. Furthermore, the plugin exhibits good practices regarding database interactions, with all SQL queries utilizing prepared statements, and it incorporates nonce and capability checks. There are also no observed file operations or external HTTP requests, reducing potential attack vectors.
However, a notable concern arises from the static analysis of output escaping, where only 5% of the 40 total outputs are properly escaped. This low rate suggests a high potential for cross-site scripting (XSS) vulnerabilities, as unsanitized output can be injected with malicious code. While the taint analysis shows no flows with unsanitized paths and no critical or high severity issues, the output escaping deficiency remains a significant risk that could be exploited if an attacker can control the data being outputted.
In conclusion, while the plugin is robust in its handling of database queries, authentication checks, and external interactions, the poor output escaping practices present a clear and present danger. The lack of historical vulnerabilities is encouraging but does not negate the risks identified in the current code. Addressing the output escaping issues should be the highest priority to improve the overall security of this plugin.
Key Concerns
- Low rate of properly escaped output
SyntaxHighlighter TinyMCE Button Security Vulnerabilities
SyntaxHighlighter TinyMCE Button Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
SyntaxHighlighter TinyMCE Button Attack Surface
WordPress Hooks 21
Maintenance & Trust
SyntaxHighlighter TinyMCE Button Maintenance & Trust
Maintenance Signals
Community Trust
SyntaxHighlighter TinyMCE Button Alternatives
WP SyntaxHighlighter
wp-syntaxhighlighter
This plugin is code syntax highlighter based on SyntaxHighlighter ver. 3.0.83 and 2.1.382.
Contact Form 7 Editor Button
cf7-editor-button
Adds a custom button to TinyMCE WordPress editor to insert shortcodes for Contact Form 7 plugin.
Auto SyntaxHighlighter
auto-syntaxhighlighter
Auto SyntaxHighlighter is a WordPress Code highlight plugin. Use editor botton, in the pop-up window, paste or write your code, oh, very simple.
Crazy Pills
crazy-pills
Build buttons, boxes, beautiful lists, and highlight text right from your editor, with live preview.
CodeMirror for CodeEditor
codemirror-for-codeeditor
Just another code syntaxhighligher for the theme and plugin editor with CodeMirror.
SyntaxHighlighter TinyMCE Button Developer Profile
7 plugins · 660 total installs
How We Detect SyntaxHighlighter TinyMCE Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/syntaxhighlighter-tinymce-button/rc-admin-js.js/wp-content/plugins/syntaxhighlighter-tinymce-button/shtb_fullscreen.css/wp-content/plugins/syntaxhighlighter-tinymce-button/rc-admin-js.jsHTML / DOM Fingerprints
syntaxhighlighter<!-- SyntaxHighlighter TinyMCE Button Options --><!-- SyntaxHighlighter TinyMCE Button Settings -->data-languagedata-brushshtb_adv_plugin_url