V7 Legacy Editor Enabler Security & Risk Analysis

wordpress.org/plugins/v7-legacy-editor-enabler

Granular control to disable Gutenberg and enable the Legacy (TinyMCE) Editor per post type with automatic settings redirect.

0 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Feb 2, 2026
block-editoreditorgutenberglegacy-editorwysiwyg
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is V7 Legacy Editor Enabler Safe to Use in 2026?

Generally Safe

Score 100/100

V7 Legacy Editor Enabler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "v7-legacy-editor-enabler" plugin version 1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events, particularly those lacking authentication or permission checks, significantly limits its potential attack surface. Furthermore, the code shows good practices with no dangerous functions identified, all SQL queries utilizing prepared statements, and a high percentage of properly escaped output. The lack of file operations and external HTTP requests further contributes to its security. The plugin also demonstrates an awareness of WordPress security mechanisms with two capability checks present. The vulnerability history being entirely clear with no recorded CVEs, of any severity, reinforces this positive assessment. This indicates a well-maintained and secure plugin.

However, the complete absence of taint analysis results and nonce checks, while potentially indicating no issues, also means there's no direct evidence of these critical security measures being implemented or tested. While the capability checks are a positive sign, a complete lack of nonce checks for any potential entry points that might exist is a concern, as this is a fundamental WordPress security practice for AJAX and other dynamic actions. The plugin's minimal entry points might explain the lack of need for these checks in the analyzed code, but it's a point worth noting for future development or potential expansion of its functionality. Overall, it's a secure plugin but could benefit from explicit demonstration of fundamental security checks like nonces.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

V7 Legacy Editor Enabler Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

V7 Legacy Editor Enabler Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

V7 Legacy Editor Enabler Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
6 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped7 total outputs
Attack Surface

V7 Legacy Editor Enabler Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedincludes\class-v7-legacy-editor-enabler.php:103
actionadmin_enqueue_scriptsincludes\class-v7-legacy-editor-enabler.php:115
actionadmin_enqueue_scriptsincludes\class-v7-legacy-editor-enabler.php:116
actionadmin_menuincludes\class-v7-legacy-editor-enabler.php:117
actionadmin_initincludes\class-v7-legacy-editor-enabler.php:118
filterplugin_action_links_v7-legacy-editor-enabler/v7-legacy-editor-enabler.phpincludes\class-v7-legacy-editor-enabler.php:119
filteruse_block_editor_for_post_typeincludes\class-v7-legacy-editor-enabler.php:131
Maintenance & Trust

V7 Legacy Editor Enabler Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 2, 2026
PHP min version7.4
Downloads126

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

V7 Legacy Editor Enabler Developer Profile

Vaibhaw Kumar

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect V7 Legacy Editor Enabler

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/v7-legacy-editor-enabler/admin/css/v7-legacy-editor-enabler-admin.css/wp-content/plugins/v7-legacy-editor-enabler/admin/js/v7-legacy-editor-enabler-admin.js
Script Paths
/wp-content/plugins/v7-legacy-editor-enabler/admin/js/v7-legacy-editor-enabler-admin.js
Version Parameters
v7-legacy-editor-enabler/admin/css/v7-legacy-editor-enabler-admin.css?ver=v7-legacy-editor-enabler/admin/js/v7-legacy-editor-enabler-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="v7_legacy_editor_posts"name="v7_legacy_editor_posts"id="v7_legacy_editor_pages"name="v7_legacy_editor_pages"
FAQ

Frequently Asked Questions about V7 Legacy Editor Enabler