
Auto Future Date Security & Risk Analysis
wordpress.org/plugins/auto-future-dateAdds an "Auto" link to your post page that will automatically schedule your next post based on the most recent post.
Is Auto Future Date Safe to Use in 2026?
Generally Safe
Score 85/100Auto Future Date has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The auto-future-date plugin v0.5.2 exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities, there are significant concerns arising from the static analysis. The presence of an unprotected AJAX handler is a critical security weakness, creating a direct attack vector that could be exploited if not properly secured by the application layer or subsequent sanitization within the handler itself. The lack of nonce checks and capability checks on this entry point further exacerbates this risk.
Additionally, the output escaping is only 40% effective, meaning a portion of the plugin's output is not properly sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities. The absence of taint analysis results and the small attack surface might mask deeper issues, but the identified unprotected AJAX handler and insufficient output escaping are immediate red flags. The plugin's clean vulnerability history is positive but does not negate the risks identified in the current code analysis.
Key Concerns
- Unprotected AJAX handler found
- Output escaping at 40%
- No nonce checks on AJAX handler
- No capability checks on AJAX handler
Auto Future Date Security Vulnerabilities
Auto Future Date Code Analysis
Output Escaping
Auto Future Date Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Auto Future Date Maintenance & Trust
Maintenance Signals
Community Trust
Auto Future Date Alternatives
Future Posts Calendar
future-posts-calendar
This plugin adds a monthly calendar that shows all the dates you have future posts.
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
post-expirator
PublishPress Future can make scheduled changes to your content. You can unpublish posts, move posts to a new status, update the categories, and more.
WP Meta and Date Remover
wp-meta-and-date-remover
Remove meta author and date information from posts and pages. Hide from Humans and Search engines.SEO friendly and most advance plugin.
Bulk Post Update Date
bulk-post-update-date
Change the Post Update date for all posts and pages in one click. This will help your blog in search engines and your blog will look alive.
WP Missed Schedule Posts
wp-missed-schedule-posts
Auto publish future/scheduled posts missed by WordPress cron
Auto Future Date Developer Profile
4 plugins · 550 total installs
How We Detect Auto Future Date
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-future-date/help.png/wp-content/plugins/auto-future-date/autoFutureDate.jsHTML / DOM Fingerprints
id="afd_minTime"id="afd_minFormatted"id="afd_maxTime"id="afd_maxFormatted"/wp-ajax.php?action=afd_get_date