
WP-Spellcheck Security & Risk Analysis
wordpress.org/plugins/wp-spellcheckTinyMCE SpellChecker API - this plugin provides action/filter hooks to allow easy customisation of the TinyMCE SpellChecker.
Is WP-Spellcheck Safe to Use in 2026?
Generally Safe
Score 85/100WP-Spellcheck has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-spellcheck" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding dangerous functions, performing 100% of its SQL queries using prepared statements, and ensuring all outputs are properly escaped. There are no recorded vulnerabilities (CVEs) or recorded taint flows, suggesting a lack of historically exploitable issues and a generally clean codebase in terms of data sanitization. The absence of file operations and external HTTP requests also reduces potential attack vectors.
However, a significant concern arises from the presence of one AJAX handler that lacks authentication checks. This represents a direct entry point into the plugin's functionality that can be accessed by unauthenticated users. While the static analysis did not reveal any specific dangerous functions or taint issues that could be exploited through this AJAX handler, the lack of authorization leaves it vulnerable to potential abuse. The absence of any nonce checks on this AJAX handler further exacerbates this risk, as it provides no mechanism to verify the legitimacy of the request.
In conclusion, the plugin's strengths lie in its secure coding practices for SQL and output handling, and its clean vulnerability history. The primary weakness is the unprotected AJAX endpoint, which, despite not having immediate exploitable flaws identified in static analysis, presents a clear security oversight. Addressing the authentication for this AJAX handler is crucial to improving the plugin's overall security.
Key Concerns
- Unprotected AJAX handler
- Missing nonce check on AJAX handler
WP-Spellcheck Security Vulnerabilities
WP-Spellcheck Code Analysis
WP-Spellcheck Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
WP-Spellcheck Maintenance & Trust
Maintenance Signals
Community Trust
WP-Spellcheck Alternatives
Black Studio TinyMCE Widget
black-studio-tinymce-widget
The visual editor widget for WordPress.
AddQuicktag
addquicktag
This plugin makes it easy to add Quicktags to the html - and visual-editor.
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor
post-and-page-builder
Post and Page Builder is a standalone plugin which adds functionality to the existing TinyMCE Editor.
Proxy Cache Purge
varnish-http-purge
Automatically empty proxy cached content when your site is modified.
IP2Location Country Blocker
ip2location-country-blocker
Blocks unwanted visitors from accessing your frontend (blog pages) or backend (admin area) by countries or proxy servers.
WP-Spellcheck Developer Profile
2 plugins · 70 total installs
How We Detect WP-Spellcheck
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
admin-ajax.php?action=spellcheck