EditorFontsize Security & Risk Analysis

wordpress.org/plugins/wp-editor-fontsize

Allows you to change a font size in a visual editor

500 active installs v1.0 PHP + WP 3.2.1+ Updated Jul 7, 2012
adminfontfontsizesizetinymce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EditorFontsize Safe to Use in 2026?

Generally Safe

Score 85/100

EditorFontsize has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "wp-editor-fontsize" plugin version 1.0 exhibits a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes that are accessible without authentication. Furthermore, the code demonstrates excellent practices regarding dangerous functions, SQL queries (all prepared), output escaping (all escaped), and file operations. The absence of external HTTP requests and the lack of recorded vulnerabilities in its history further bolster its security. However, a significant concern arises from the complete absence of nonce checks and capability checks. While the current version has a limited attack surface that might not immediately expose this weakness, it represents a potential oversight that could be exploited if the plugin's functionality were to expand or if an attacker found an indirect way to trigger code execution. This lack of explicit authorization checks is the primary area of concern despite an otherwise clean bill of health.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

EditorFontsize Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

EditorFontsize Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

EditorFontsize Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filtermce_buttons_2wp-editor-fontsize.php:19
Maintenance & Trust

EditorFontsize Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedJul 7, 2012
PHP min version
Downloads16K

Community Trust

Rating100/100
Number of ratings6
Active installs500
Developer Profile

EditorFontsize Developer Profile

kubenstein

1 plugin · 500 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EditorFontsize

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-editor-fontsize/wp-editor-fontsize.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about EditorFontsize