
Advanced Editor Tools Security & Risk Analysis
wordpress.org/plugins/tinymce-advancedExtends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Is Advanced Editor Tools Safe to Use in 2026?
Generally Safe
Score 100/100Advanced Editor Tools has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of tinymce-advanced v5.9.2 reveals a generally strong security posture with a minimal attack surface and robust practices around SQL queries, nonce checks, and capability checks. The absence of any critical or high-severity taint flows is also a positive sign. However, a significant concern is the low percentage of properly escaped output (9%), indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care in the majority of output contexts. The presence of a single file operation is also a point of attention, though its risk depends entirely on the specifics of its implementation, which are not detailed here. Despite a history of past vulnerabilities, including a medium severity one, the fact that all known CVEs are patched suggests the developers have addressed past issues. The low number of entry points and the absence of unprotected ones are excellent security hygiene, but the output escaping weakness, if exploited, could still lead to significant risk.
Key Concerns
- Low percentage of properly escaped output
- Bundled TinyMCE v5.9.2 library
- One file operation present
Advanced Editor Tools Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
TinyMCE Advanced <= 4.1.9 - Cross-Site Request Forgery
Advanced Editor Tools Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Advanced Editor Tools Attack Surface
WordPress Hooks 21
Maintenance & Trust
Advanced Editor Tools Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Editor Tools Alternatives
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Disable Gutenberg
disable-gutenberg
Disable Gutenberg Block Editor and restore the Classic Editor and original Edit Post screen (TinyMCE, meta boxes, etc.).
Classic Editor and Classic Widgets
classic-editor-and-classic-widgets
Disables Gutenberg editor totally everywhere and enables Classic Editor and Classic Widgets.
Enable Classic Editor & Widgets
enable-classic-editor
A simple & lightweight plugin to enable the classic editor on WordPress with advanced configuration options.
Guten Free Options
guten-free-options
Gutenberg Free Options for your WordPressed Burger err I mean Editor.
Advanced Editor Tools Developer Profile
6 plugins · 2.0M total installs
How We Detect Advanced Editor Tools
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tinymce-advanced/plugin-assets/tadv.css/wp-content/plugins/tinymce-advanced/plugin-assets/tadv.js/wp-content/plugins/tinymce-advanced/plugin-assets/tadv.jstinymce-advanced/plugin-assets/tadv.css?ver=tinymce-advanced/plugin-assets/tadv.js?ver=HTML / DOM Fingerprints
<!-- Advanced Editor Tools Settings --><!-- Advanced Editor Tools Settings End -->