TinyMCE Clear Float Security & Risk Analysis

wordpress.org/plugins/tinymce-clear-buttons

Adds a button to the WordPress TinyMCE editor to clear floats.

10K active installs v1.3.2 PHP + WP 4.6+ Updated Aug 1, 2018
clearclear-floatsformattingtinymcewordpress-editor
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TinyMCE Clear Float Safe to Use in 2026?

Generally Safe

Score 85/100

TinyMCE Clear Float has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'tinymce-clear-buttons' plugin v1.3.2 demonstrates a strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and all outputs being properly escaped. The presence of a capability check, while only one, is also a positive sign. The lack of any recorded vulnerabilities or CVEs further reinforces its current secure status.

The analysis shows no identified taint flows, which is excellent. The only potential area of concern, albeit minor and not directly indicating a vulnerability in this specific version, is the use of a bundled library (TinyMCE v1.3.2). While this version might be secure, outdated bundled libraries can become a security risk over time if not actively maintained or updated to address newly discovered vulnerabilities in the core library. However, given the current analysis and vulnerability history, this is a low-impact observation.

In conclusion, 'tinymce-clear-buttons' v1.3.2 appears to be a very secure plugin with excellent coding practices evident in the static analysis. The extremely limited attack surface and adherence to secure coding principles like prepared statements and output escaping are significant strengths. The absence of any historical vulnerabilities further bolsters confidence. The only consideration for future maintenance would be ensuring the bundled TinyMCE library remains up-to-date.

Key Concerns

  • Bundled library TinyMCE v1.3.2 is not explicitly up-to-date
Vulnerabilities
None known

TinyMCE Clear Float Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TinyMCE Clear Float Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE1.3.2

Output Escaping

100% escaped2 total outputs
Attack Surface

TinyMCE Clear Float Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filtermce_buttons_2includes\class-tinymce-clear-float.php:118
filtermce_cssincludes\class-tinymce-clear-float.php:119
filtermce_external_languagesincludes\class-tinymce-clear-float.php:120
filtermce_external_pluginsincludes\class-tinymce-clear-float.php:121
filterplugin_row_metaincludes\class-tinymce-clear-float.php:122
Maintenance & Trust

TinyMCE Clear Float Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 1, 2018
PHP min version
Downloads72K

Community Trust

Rating100/100
Number of ratings6
Active installs10K
Developer Profile

TinyMCE Clear Float Developer Profile

Philipp Bammes

2 plugins · 12K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TinyMCE Clear Float

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tinymce-clear-buttons/admin/css/style.css/wp-content/plugins/tinymce-clear-buttons/admin/js/tinymce-clear-button-script.js
Script Paths
/wp-content/plugins/tinymce-clear-buttons/admin/js/tinymce-clear-button-script.js
Version Parameters
/wp-content/plugins/tinymce-clear-buttons/admin/css/style.css?ver=/wp-content/plugins/tinymce-clear-buttons/admin/js/tinymce-clear-button-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
mce-btnmce-i-clear-float
Data Attributes
data-mce-toolbar-btn
JS Globals
tinymce_clear_button_script
FAQ

Frequently Asked Questions about TinyMCE Clear Float