TinyMCE Chinese Convert Security & Risk Analysis

wordpress.org/plugins/tinymce-chinese-convert

一鍵在部落格「文章編輯」頁面將你的文章轉換為簡體或繁體

100 active installs v1.2.6 PHP + WP 3.0+ Updated Jul 29, 2021
chineseposttinymce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TinyMCE Chinese Convert Safe to Use in 2026?

Generally Safe

Score 85/100

TinyMCE Chinese Convert has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "tinymce-chinese-convert" v1.2.6 plugin demonstrates a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unsanitized taint flows, raw SQL queries, or unescaped output is highly commendable. Furthermore, the plugin appears to implement capability checks, which is a good practice for restricting access to potentially sensitive operations. The zero known vulnerabilities in its history also suggest a consistent focus on security by the developers.

However, the analysis indicates a complete lack of entry points such as AJAX handlers, REST API routes, shortcodes, or cron events. While this reduces the attack surface to zero, it also raises questions about the plugin's actual functionality and how it integrates with WordPress. If the plugin is intended to provide any interactive features, the absence of these entry points could be a sign of incomplete development or a misunderstanding of how plugins typically interact with the WordPress ecosystem. The presence of bundled libraries, specifically TinyMCE v1.2.6, is noted. While not flagged as a direct issue in this analysis, outdated bundled libraries can become a security risk over time if not updated, even if the core plugin code is secure.

Key Concerns

  • Bundled library outdated: TinyMCE v1.2.6
Vulnerabilities
None known

TinyMCE Chinese Convert Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TinyMCE Chinese Convert Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE1.2.6
Attack Surface

TinyMCE Chinese Convert Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_enqueue_scriptstinymce-chinese-convert.php:42
filtermce_external_pluginstinymce-chinese-convert.php:62
filtermce_buttonstinymce-chinese-convert.php:63
filtermce_external_pluginstinymce-chinese-convert.php:73
filtermce_buttonstinymce-chinese-convert.php:74
actioninittinymce-chinese-convert.php:78
actioninittinymce-chinese-convert.php:79
Maintenance & Trust

TinyMCE Chinese Convert Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 29, 2021
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings4
Active installs100
Developer Profile

TinyMCE Chinese Convert Developer Profile

Arefly

24 plugins · 2K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TinyMCE Chinese Convert

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tinymce-chinese-convert/convert_simplified.min.js/wp-content/plugins/tinymce-chinese-convert/convert_traditional.min.js/wp-content/plugins/tinymce-chinese-convert/convert.min.js
Script Paths
//file.arefly.com/convert_to_difference_locate.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about TinyMCE Chinese Convert