
TinyMCE Table Security & Risk Analysis
wordpress.org/plugins/tinymce-tableAjoute la création et l'édition des tables à TinyMCE
Is TinyMCE Table Safe to Use in 2026?
Generally Safe
Score 85/100TinyMCE Table has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tinymce-table" v1.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and a clean taint analysis suggest a well-written and securely coded plugin. Furthermore, the lack of any recorded vulnerabilities, including critical or high-severity ones, reinforces this positive assessment. The plugin demonstrates good practices by not exposing a significant attack surface and by adhering to secure coding principles where data handling is concerned.
However, there are a few areas that warrant consideration. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events, while contributing to a zero attack surface, might also indicate limited functionality or a plugin that is not actively interacting with WordPress in dynamic ways. More importantly, the complete lack of nonce checks and capability checks across all potential entry points is a significant concern. While the static analysis shows no entry points, if any were to be introduced or if the analysis is incomplete, the absence of these fundamental WordPress security mechanisms leaves the plugin vulnerable to unauthorized actions or cross-site request forgery. The bundling of TinyMCE v1.0, while not a critical issue, could also present a minor risk if this specific version has known, though unexploited, vulnerabilities.
Key Concerns
- Missing nonce checks on potential entry points
- Missing capability checks on potential entry points
- Bundled outdated library (TinyMCE v1.0)
TinyMCE Table Security Vulnerabilities
TinyMCE Table Code Analysis
Bundled Libraries
TinyMCE Table Attack Surface
WordPress Hooks 2
Maintenance & Trust
TinyMCE Table Maintenance & Trust
Maintenance Signals
Community Trust
TinyMCE Table Alternatives
WP TinyMCE Tables
wp-tinymce-tables
Adds the table controls to the TinyMCE editor in WordPress
AddQuicktag
addquicktag
This plugin makes it easy to add Quicktags to the html - and visual-editor.
Manage TinyMCE Editor
manage-tinymce-editor
Add buttons to TinyMCE, WordPress' default visual editor.
Safer Email Link
safer-email-link
Adds a button to the TinyMCE to wrap an email address with a shortcode using the WordPress antispambot function.
Crazy Pills
crazy-pills
Build buttons, boxes, beautiful lists, and highlight text right from your editor, with live preview.
TinyMCE Table Developer Profile
1 plugin · 700 total installs
How We Detect TinyMCE Table
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tinymce-table/plugin.min.js/wp-content/plugins/tinymce-table/plugin.min.jstinymce-table/plugin.min.js?ver=HTML / DOM Fingerprints
tinymce.plugins.table