
TinyMCE Clear Float Security & Risk Analysis
wordpress.org/plugins/tinymce-clear-buttonsAdds a button to the WordPress TinyMCE editor to clear floats.
Is TinyMCE Clear Float Safe to Use in 2026?
Generally Safe
Score 85/100TinyMCE Clear Float has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'tinymce-clear-buttons' plugin v1.3.2 demonstrates a strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and all outputs being properly escaped. The presence of a capability check, while only one, is also a positive sign. The lack of any recorded vulnerabilities or CVEs further reinforces its current secure status.
The analysis shows no identified taint flows, which is excellent. The only potential area of concern, albeit minor and not directly indicating a vulnerability in this specific version, is the use of a bundled library (TinyMCE v1.3.2). While this version might be secure, outdated bundled libraries can become a security risk over time if not actively maintained or updated to address newly discovered vulnerabilities in the core library. However, given the current analysis and vulnerability history, this is a low-impact observation.
In conclusion, 'tinymce-clear-buttons' v1.3.2 appears to be a very secure plugin with excellent coding practices evident in the static analysis. The extremely limited attack surface and adherence to secure coding principles like prepared statements and output escaping are significant strengths. The absence of any historical vulnerabilities further bolsters confidence. The only consideration for future maintenance would be ensuring the bundled TinyMCE library remains up-to-date.
Key Concerns
- Bundled library TinyMCE v1.3.2 is not explicitly up-to-date
TinyMCE Clear Float Security Vulnerabilities
TinyMCE Clear Float Code Analysis
Bundled Libraries
Output Escaping
TinyMCE Clear Float Attack Surface
WordPress Hooks 5
Maintenance & Trust
TinyMCE Clear Float Maintenance & Trust
Maintenance Signals
Community Trust
TinyMCE Clear Float Alternatives
Advanced Image Styles
advanced-image-styles
Adjust an image's margins and border with ease in the Visual editor.
Clear Floats Button
clear-floats-button
Adds clear float button to TinyMCE Editor.
WP-RTL
wp-rtl
Adds two buttons to the TinyMCE editor to enable writing text in Left to Right (LTR) and Right to Left (RTL) directions.
WP Super Edit
wp-super-edit
Get control of the WordPress wysiwyg visual editor and add some functionality with more buttons and custom TinyMCE plugins.
TinyMCE Code Formatting
tinymce-code-formatting
Adds the Pre and Code buttons to the TinyMCE toolbar with customizable shortcuts
TinyMCE Clear Float Developer Profile
2 plugins · 12K total installs
How We Detect TinyMCE Clear Float
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tinymce-clear-buttons/admin/css/style.css/wp-content/plugins/tinymce-clear-buttons/admin/js/tinymce-clear-button-script.js/wp-content/plugins/tinymce-clear-buttons/admin/js/tinymce-clear-button-script.js/wp-content/plugins/tinymce-clear-buttons/admin/css/style.css?ver=/wp-content/plugins/tinymce-clear-buttons/admin/js/tinymce-clear-button-script.js?ver=HTML / DOM Fingerprints
mce-btnmce-i-clear-floatdata-mce-toolbar-btntinymce_clear_button_script