tinyWYM Editor Security & Risk Analysis

wordpress.org/plugins/tinywym-editor

Convert WordPress's WYSIWYG editor into a WYSIWYM editor. Add and edit any HTML tag and attribute from the visual editor.

1K active installs v1.4.1 PHP + WP 4.2.0+ Updated Mar 12, 2018
tinymcevisual-editorwp-editorwysiwygwysiwym
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is tinyWYM Editor Safe to Use in 2026?

Generally Safe

Score 85/100

tinyWYM Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of tinyMCE-editor v1.4.1 indicates a generally strong security posture regarding core input validation and data handling. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, all identified SQL queries utilize prepared statements, and there are no indications of file operations, external HTTP requests, or taint flows, which are all positive security indicators. The presence of nine capability checks suggests an intent to properly restrict access to certain functionalities. However, a significant concern arises from the output escaping signal, where 100% of the seven identified outputs are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into content displayed by the plugin. The lack of documented vulnerabilities in its history is positive, suggesting a history of secure development or a low profile. Overall, while the plugin demonstrates good practices in areas like SQL handling and attack surface minimization, the unescaped output is a critical weakness that needs immediate attention to mitigate XSS risks.

Key Concerns

  • All outputs are unescaped
Vulnerabilities
None known

tinyWYM Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

tinyWYM Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
9
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

tinyWYM Editor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedtinywym-editor.php:33
actionadmin_inittinywym-editor.php:56
filtermce_csstinywym-editor.php:72
actioninittinywym-editor.php:87
filtermce_external_pluginstinywym-editor.php:130
filtermce_buttonstinywym-editor.php:131
actionadmin_enqueue_scriptstinywym-editor.php:134
actionwp_enqueue_scriptstinywym-editor.php:138
filtermce_external_languagestinywym-editor.php:144
actionadmin_menutwym-admin-settings.php:14
actionadmin_inittwym-admin-settings.php:26
Maintenance & Trust

tinyWYM Editor Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 12, 2018
PHP min version
Downloads68K

Community Trust

Rating100/100
Number of ratings6
Active installs1K
Developer Profile

tinyWYM Editor Developer Profile

arickards

1 plugin · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect tinyWYM Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tinywym-editor/css/tinywym-styles.css/wp-content/plugins/tinywym-editor/js/mce-plugin.js/wp-content/plugins/tinywym-editor/js/tinywym-hidden.js/wp-content/plugins/tinywym-editor/css/modal-styles.css
Script Paths
/wp-content/plugins/tinywym-editor/js/mce-plugin.js/wp-content/plugins/tinywym-editor/js/tinywym-hidden.js
Version Parameters
tinywym-editor/css/tinywym-styles.css?ver=tinywym-editor/css/modal-styles.css?ver=tinywym-editor/js/mce-plugin.js?ver=tinywym-editor/js/tinywym-hidden.js?ver=

HTML / DOM Fingerprints

JS Globals
tinyWYMtinyWYM_hidden
FAQ

Frequently Asked Questions about tinyWYM Editor