TinyMCE Pre Button Security & Risk Analysis

wordpress.org/plugins/tinymce-pre-button

Adds the Pre button to the TinyMCE toolbar and the shortcut Ctrl+0 to format text with <pre> tag

30 active installs v1.0 PHP + WP 4.1+ Updated Mar 26, 2015
buttoneditorformattingshortcuttinymce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is TinyMCE Pre Button Safe to Use in 2026?

Generally Safe

Score 85/100

TinyMCE Pre Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "tinymce-pre-button" plugin v1.0 exhibits an excellent security posture based on the provided static analysis. The absence of any detected dangerous functions, SQL queries without prepared statements, unescaped output, file operations, external HTTP requests, nonce checks, capability checks, or taint flows is a strong indicator of well-written and secure code. The plugin also presents a minimal attack surface, with no apparent entry points that are unprotected.

The vulnerability history is equally positive, showing no known CVEs, either past or present. This lack of historical vulnerabilities, combined with the clean static analysis, suggests a mature and consistently secure development process for this plugin. The bundling of TinyMCE v1.0, while noted, does not pose an immediate security concern given the absence of other exploitable weaknesses in the plugin itself.

In conclusion, the "tinymce-pre-button" plugin v1.0 appears to be a highly secure option. Its strengths lie in its robust coding practices, lack of exploitable attack surface, and clean vulnerability history. There are no discernible risks or areas for deduction based on the provided data.

Vulnerabilities
None known

TinyMCE Pre Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TinyMCE Pre Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE1.0
Attack Surface

TinyMCE Pre Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtermce_external_pluginstinymce-pre-button.php:25
filtermce_buttonstinymce-pre-button.php:26
actioninittinymce-pre-button.php:28
Maintenance & Trust

TinyMCE Pre Button Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedMar 26, 2015
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

TinyMCE Pre Button Developer Profile

mortalis

3 plugins · 310 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TinyMCE Pre Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tinymce-pre-button/mce-pre/plugin.js
Script Paths
/wp-content/plugins/tinymce-pre-button/mce-pre/plugin.js

HTML / DOM Fingerprints

JS Globals
window.tinymce.plugins.preButton
FAQ

Frequently Asked Questions about TinyMCE Pre Button