
Auto Post Publisher Security & Risk Analysis
wordpress.org/plugins/auto-post-publisherAutomatically publishes scheduled posts that may have missed their scheduled time.
Is Auto Post Publisher Safe to Use in 2026?
Generally Safe
Score 100/100Auto Post Publisher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "auto-post-publisher" plugin version 1.8 exhibits a strong security posture. The absence of any identified dangerous functions, unsanitized taint flows, or raw SQL queries is highly commendable. Furthermore, all SQL queries are properly prepared, and all identified output operations are correctly escaped, indicating good developer practices in handling data. The plugin also demonstrates awareness of WordPress security mechanisms by including at least one capability check.
However, there are areas for improvement. The complete lack of nonce checks on AJAX handlers, REST API routes, shortcodes, and cron events, combined with zero identified entry points needing authentication, raises a concern. While the current analysis found no unprotected entry points, this could indicate a very limited attack surface or simply that the analysis missed potential avenues for interaction. The vulnerability history is clean, which is a significant positive, suggesting a history of secure development. Nevertheless, the absence of nonce checks is a potential weakness that could be exploited if any new entry points are introduced or discovered that bypass existing checks.
In conclusion, "auto-post-publisher" v1.8 appears to be a securely coded plugin with robust data handling. The lack of any historical vulnerabilities is a strong indicator of its reliability. The primary area of potential weakness lies in the absence of nonce checks, which, while not leading to any identified issues in this specific version, is a standard security practice that should be implemented to proactively defend against future threats, especially as the plugin evolves.
Key Concerns
- No nonce checks on AJAX, REST, shortcodes, or cron
Auto Post Publisher Security Vulnerabilities
Auto Post Publisher Code Analysis
SQL Query Safety
Output Escaping
Auto Post Publisher Attack Surface
WordPress Hooks 5
Maintenance & Trust
Auto Post Publisher Maintenance & Trust
Maintenance Signals
Community Trust
Auto Post Publisher Alternatives
Social Media Auto Poster – Schedule & Publish to Buffer
wp-to-buffer
Automatically post and schedule your WordPress content to Facebook, X/Twitter, LinkedIn, Threads, Bluesky, and more social networks using Buffer.
Smart Tag Insert
smart-tag-insert
Automatically adds most relevant tags to posts selecting them from an admin-defined list.
Simple Auto Post Scheduler
simple-auto-post-scheduler
Schedule posts to be published at specific times and intervals with an easy-to-use interface.
RSS Feed Reader by Enebrus Kem Lem
ekl-rss-feed-reader
Reads RSS Feeds automatically and publish their posts in your site linking the original site.
ReVivify Social
revivify-social
Plugin that facilitates auto post sharing and scheduling on social networks, keeping the content alive and active.
Auto Post Publisher Developer Profile
1 plugin · 20 total installs
How We Detect Auto Post Publisher
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-post-publisher/assets/css/admin-style.css/wp-content/plugins/auto-post-publisher/assets/js/admin-script.js/wp-content/plugins/auto-post-publisher/assets/js/admin-script.jsauto-post-publisher/assets/css/admin-style.css?ver=auto-post-publisher/assets/js/admin-script.js?ver=HTML / DOM Fingerprints
wrapform-tablename="auto_post_publisher_settings"id="auto_post_publisher_settings"value="auto_post_publisher_settings"name="auto_post_publisher_settings[post_types][]"