
TinyMCE Generic WP Shortcode Editor Security & Risk Analysis
wordpress.org/plugins/tinymce-generic-wp-shortcode-editorIt makes TinyMCE able to create or edit shortcodes in a visual way.
Is TinyMCE Generic WP Shortcode Editor Safe to Use in 2026?
Generally Safe
Score 85/100TinyMCE Generic WP Shortcode Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "tinymce-generic-wp-shortcode-editor" v1.0 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin has no recorded vulnerabilities, which is a strong indicator of a well-maintained and secure codebase. Furthermore, it demonstrates good development practices by utilizing prepared statements for all SQL queries and has no apparent critical or high-severity taint flows. The absence of external HTTP requests and file operations further reduces its attack surface. However, a significant concern is the complete lack of output escaping for its 4 identified outputs. This means that any data processed and displayed by the plugin could potentially be vulnerable to Cross-Site Scripting (XSS) attacks if the input is not sufficiently sanitized before reaching the output stage. While the plugin has capability checks, the lack of nonce checks for potential AJAX handlers or other entry points (even though none are currently exposed) represents a missed opportunity for strengthening its security against common WordPress attack vectors.
Key Concerns
- Output escaping not implemented
- Missing nonce checks
TinyMCE Generic WP Shortcode Editor Security Vulnerabilities
TinyMCE Generic WP Shortcode Editor Code Analysis
Bundled Libraries
Output Escaping
TinyMCE Generic WP Shortcode Editor Attack Surface
WordPress Hooks 4
Maintenance & Trust
TinyMCE Generic WP Shortcode Editor Maintenance & Trust
Maintenance Signals
Community Trust
TinyMCE Generic WP Shortcode Editor Alternatives
Crazy Pills
crazy-pills
Build buttons, boxes, beautiful lists, and highlight text right from your editor, with live preview.
Easy Tinymce Editor Add Button
easy-tinymce-editor-add-button
Simple plugin for adding buttons to the html wp panel of the tinymce editor. Features: Ease of use Ability to add any content Unlimited number of b …
DCO Shortcodes Menu
dco-shortcodes-menu
Allow you to add shortcodes menu to the editor
Priority Shortcodes
priority-shortcodes
Processes specific shortcodes before wpautop() and do_shortcode()
Kabook Editor Tools
kabook-editor-tools
Supercharge WordPress: Modular UI Elements, Image Effects, Sticky Media Player & a unified Toolkit for Classic & Gutenberg.
TinyMCE Generic WP Shortcode Editor Developer Profile
2 plugins · 30 total installs
How We Detect TinyMCE Generic WP Shortcode Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tinymce-generic-wp-shortcode-editor/tinymce/plugins/shortcode-editor/shortcode_editor.js/wp-content/plugins/tinymce-generic-wp-shortcode-editor/tinymce/plugins/shortcode-editor/shortcode_editor.jsHTML / DOM Fingerprints
id="gse_new_prop_name"id="gse_new_prop_value"id="gse_npn_label"id="gse_npa_label"id="gse_properties"id="gse_uncheck_prop"+7 moregse_shortcode_eraddLoadEventtinyMCEPopupmakeShortcodeupdatePropertyaddProperty+7 more[][/sc_id