TC Perfect Tools Security & Risk Analysis

wordpress.org/plugins/tc-perfect-tools

Extend your Elementor and Elementor Pro with this plugin. It offers various capabilities such as tooltips, restricted content and more

0 active installs v1.0.2 PHP 5.6+ WP 5.1+ Updated Feb 28, 2022
custom-jselementorrestricted-contenttoolstooltips
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TC Perfect Tools Safe to Use in 2026?

Generally Safe

Score 85/100

TC Perfect Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

Based on the static analysis, the "tc-perfect-tools" plugin v1.0.2 exhibits a strong security posture in several key areas. The absence of any identified dangerous functions, SQL queries not using prepared statements, file operations, or external HTTP requests is commendable. Furthermore, the plugin does not appear to rely on bundled libraries, which often introduce outdated and vulnerable components. The vulnerability history also shows a clean slate, with no known CVEs recorded, suggesting a history of secure development or diligent patching if any issues have arisen historically.

However, there are notable areas of concern that detract from an otherwise positive assessment. The complete lack of nonce checks and capability checks across all entry points (even though the attack surface is currently zero) presents a significant latent risk. Should any AJAX handlers, REST API routes, shortcodes, or cron events be added in future versions without proper authentication and authorization mechanisms, they would be immediately vulnerable. Additionally, the low rate of properly escaped output (25%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities if user-supplied data is ever rendered on the frontend without adequate sanitization.

In conclusion, while the "tc-perfect-tools" plugin has a promising foundation with no current known vulnerabilities and good practices regarding SQL and dangerous functions, the lack of fundamental security checks like nonces and capability checks, coupled with poor output escaping, presents a substantial future risk. Future development must prioritize addressing these critical oversights to maintain a secure application.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Low percentage of properly escaped output
Vulnerabilities
None known

TC Perfect Tools Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

TC Perfect Tools Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped4 total outputs
Attack Surface

TC Perfect Tools Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionelementor/element/after_section_endmodules\custom-js\module.php:131
actionelementor/frontend/before_enqueue_scriptsmodules\custom-js\module.php:132
actionelementor/frontend/after_rendermodules\custom-js\module.php:133
actionelementor/element/after_section_endmodules\restricted-content\module.php:168
actionelementor/widget/render_contentmodules\restricted-content\module.php:171
actionelementor/frontend/section/should_rendermodules\restricted-content\module.php:174
actionelementor/frontend/column/should_rendermodules\restricted-content\module.php:175
actionelementor/frontend/section/after_rendermodules\restricted-content\module.php:177
actionelementor/frontend/column/after_rendermodules\restricted-content\module.php:178
actionelementor/element/after_section_endmodules\tooltip\module.php:264
actionelementor/widget/before_render_contentmodules\tooltip\module.php:267
actionelementor/frontend/section/before_rendermodules\tooltip\module.php:268
actionelementor/widget/render_contentmodules\tooltip\module.php:271
actionelementor/frontend/section/after_rendermodules\tooltip\module.php:272
actionelementor/initplugin.php:24
actionplugins_loadedtc-perfect-tools.php:44
Maintenance & Trust

TC Perfect Tools Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedFeb 28, 2022
PHP min version5.6
Downloads953

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TC Perfect Tools Developer Profile

Thomas Cocchiara

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TC Perfect Tools

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tc-perfect-tools/modules/custom-js/assets/empty.js/wp-content/plugins/tc-perfect-tools/modules/tooltip/assets/style.css/wp-content/plugins/tc-perfect-tools/modules/tooltip/assets/script.js/wp-content/plugins/tc-perfect-tools/modules/restricted-content/assets/style.css/wp-content/plugins/tc-perfect-tools/modules/restricted-content/assets/script.js/wp-content/plugins/tc-perfect-tools/modules/custom-js/assets/style.css/wp-content/plugins/tc-perfect-tools/modules/custom-js/assets/script.js
Script Paths
/wp-content/plugins/tc-perfect-tools/modules/custom-js/assets/empty.js
Version Parameters
tc_perfect_tools_modules_urltc-perfect-tools-custom-jstc-perfect-tools-custom-js-tc_custom_js_styletc_custom_js_scripttc_tooltip_styletc_tooltip_scripttc_restricted_content_styletc_restricted_content_script

HTML / DOM Fingerprints

JS Globals
TCPerfectTools
FAQ

Frequently Asked Questions about TC Perfect Tools