
TinyMCE Code Formatting Security & Risk Analysis
wordpress.org/plugins/tinymce-code-formattingAdds the Pre and Code buttons to the TinyMCE toolbar with customizable shortcuts
Is TinyMCE Code Formatting Safe to Use in 2026?
Generally Safe
Score 85/100TinyMCE Code Formatting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tinymce-code-formatting" plugin, version 1.0.0, exhibits a very strong static security posture based on the provided analysis. The absence of any identified attack surface points, dangerous functions, raw SQL queries, file operations, or external HTTP requests is a significant positive indicator. Furthermore, the complete lack of taint analysis findings suggests that the code is likely free from common injection vulnerabilities.
However, a critical concern arises from the output escaping analysis, which shows that 100% of the two identified output points are not properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, where attackers could inject malicious scripts into the site's output. The plugin also has no recorded vulnerability history, which is good, but combined with the lack of capability and nonce checks, it might suggest the plugin hasn't been extensively tested or exposed to real-world attack scenarios that would typically uncover such issues. While the plugin's limited functionality and apparent lack of direct user interaction points mitigate immediate severe risks, the unescaped output remains a notable weakness that should be addressed.
Key Concerns
- Unescaped output detected
TinyMCE Code Formatting Security Vulnerabilities
TinyMCE Code Formatting Code Analysis
Bundled Libraries
Output Escaping
TinyMCE Code Formatting Attack Surface
WordPress Hooks 4
Maintenance & Trust
TinyMCE Code Formatting Maintenance & Trust
Maintenance Signals
Community Trust
TinyMCE Code Formatting Alternatives
TinyMCE Pre Button
tinymce-pre-button
Adds the Pre button to the TinyMCE toolbar and the shortcut Ctrl+0 to format text with <pre> tag
AddQuicktag
addquicktag
This plugin makes it easy to add Quicktags to the html - and visual-editor.
Advanced Image Styles
advanced-image-styles
Adjust an image's margins and border with ease in the Visual editor.
TinyMCE Clear Float
tinymce-clear-buttons
Adds a button to the WordPress TinyMCE editor to clear floats.
WP Super Edit
wp-super-edit
Get control of the WordPress wysiwyg visual editor and add some functionality with more buttons and custom TinyMCE plugins.
TinyMCE Code Formatting Developer Profile
3 plugins · 310 total installs
How We Detect TinyMCE Code Formatting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tinymce-code-formatting/lib/functions.js/wp-content/plugins/tinymce-code-formatting/lib/options.css/wp-content/plugins/tinymce-code-formatting/lib/options.jsmce-pre/plugin.jsmcecode-functions?ver=1.0.0mcecode-options?ver=1.0.0HTML / DOM Fingerprints
pre_shortcutcode_shortcut