TinyMce editor Font FIX Security & Risk Analysis

wordpress.org/plugins/tinymce-editor-font-fix

Built to run on EVERY install you have, TinyMce editor Font FIX changes unneeded css of the Tinymce editor.

100 active installs v1.0 PHP + WP 3.0+ Updated Jul 31, 2012
editoreditor-fixtinytinymcetinymce-editor
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TinyMce editor Font FIX Safe to Use in 2026?

Generally Safe

Score 85/100

TinyMce editor Font FIX has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The plugin 'tinymce-editor-font-fix' v1.0 exhibits a very strong security posture based on the provided static analysis. The absence of any detected dangerous functions, unsanitized taint flows, direct SQL queries, or file operations is highly commendable. Furthermore, the complete absence of unescaped output and the commitment to using prepared statements for any database interactions demonstrate excellent secure coding practices. The plugin also appears to have no known historical vulnerabilities, which further reinforces its current security standing. The primary concern is the complete lack of any entry points that require authentication checks, including AJAX handlers, REST API routes, or cron events. While this might indicate a very simple plugin with limited functionality, it also means that if any future vulnerabilities were introduced, they could potentially be exploited by unauthenticated users without any built-in defenses. The plugin does bundle TinyMCE v1.0, which while not flagged as a specific issue, could be a point of concern if it's an older, unpatched version of the library itself, although no specific vulnerabilities are indicated for it in this report.

Key Concerns

  • No capability checks implemented
  • No nonce checks implemented
  • Bundled outdated library (TinyMCE v1.0)
Vulnerabilities
None known

TinyMce editor Font FIX Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TinyMce editor Font FIX Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE1.0
Attack Surface

TinyMce editor Font FIX Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filtermce_csswebist-tinymce.php:21
filteradmin_footer_textwebist-tinymce.php:27
Maintenance & Trust

TinyMce editor Font FIX Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedJul 31, 2012
PHP min version
Downloads15K

Community Trust

Rating66/100
Number of ratings3
Active installs100
Developer Profile

TinyMce editor Font FIX Developer Profile

Yossi Jana

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TinyMce editor Font FIX

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tinymce-editor-font-fix/css-fix/webist-editor.css

HTML / DOM Fingerprints

Shortcode Output
<span id="footer-thankyou"><a href="http://www.webist.co.il" target="_blank"><img src="http://www.webist.co.il/banners/logos/logo-webist-tr.png" width="80" height="19"></a></span><p>תודה שבחרת להשתמש בתוסף של ווביסט. כדי לקבל תמיכה ומידע נוסף ניתן לגשת לאתר <a>באמצעות לחיצה על הלינק</a>. יותר מידע ניתן לקבל ב: <a href="http://www.webist.co.il" target="_blank">Webist</a></p> <p>Thank you for using TinyMCE editor Font FIX plugin, and we will appriciate your support by linking back to us or share this plugin with others.</a> - <a href="http://www.webist.co.il" target="_blank">Webist</a></p>
FAQ

Frequently Asked Questions about TinyMce editor Font FIX