
Auto Prune Posts Security & Risk Analysis
wordpress.org/plugins/auto-prune-postsAuto deletes expires (prunes) posts after a certain amount of time. On a per category basis (single category, or all at once.
Is Auto Prune Posts Safe to Use in 2026?
Generally Safe
Score 96/100Auto Prune Posts has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of "auto-prune-posts" v3.1.1 indicates a generally good security posture with no identified critical or high-severity vulnerabilities in the provided code signals. The absence of AJAX handlers, REST API routes, shortcodes, and cron events without proper authentication or permission checks significantly limits the plugin's direct attack surface. Furthermore, the plugin utilizes prepared statements for all SQL queries and has a limited number of file operations, external HTTP requests, and no bundled libraries, which are all positive security indicators. However, a concerning aspect is the relatively low rate of properly escaped output (33%), suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs are rendered in sensitive contexts. The presence of nonces and capability checks, while positive, are not universally applied to all potential entry points, which could be a weakness if new entry points are introduced without them.
Key Concerns
- 33% of outputs are not properly escaped
- Vulnerability history shows 3 medium CVEs
Auto Prune Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Auto Prune Posts <= 3.0.0 - Cross-Site Request Forgery
Auto Prune Posts <= 2.0.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Auto Prune Posts <= 1.8.0 - Cross-Site Request Forgery via admin_menu
Auto Prune Posts Code Analysis
Output Escaping
Auto Prune Posts Attack Surface
WordPress Hooks 3
Maintenance & Trust
Auto Prune Posts Maintenance & Trust
Maintenance Signals
Community Trust
Auto Prune Posts Alternatives
Mass Delete Unused Tags
mass-delete-unused-tags
Deletes all unused tags, handy tool if you want to start over with a quick clean blog.
WP Bulk Delete
wp-bulk-delete
Delete posts, pages, comments, users, taxonomy terms and meta fields in bulk with different powerful filters and conditions.
Optimize Database after Deleting Revisions
rvg-optimize-database
One-click database optimization with precise revision cleanup and flexible scheduling. Speeding up sites since 2011!
Bulk Delete
bulk-delete
Bulk delete posts, pages, users, attachments, and meta fields based on complex bulk conditions & filters.
Delete Duplicate Posts
delete-duplicate-posts
Get rid of duplicate posts and pages (any post type) on your blog with manual or automatic modes.
Auto Prune Posts Developer Profile
12 plugins · 5K total installs
How We Detect Auto Prune Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-prune-posts/css/admin.css/wp-content/plugins/auto-prune-posts/css/style.css/wp-content/plugins/auto-prune-posts/js/admin.jsauto-prune-posts/css/admin.css?ver=auto-prune-posts/css/style.css?ver=auto-prune-posts/js/admin.js?ver=HTML / DOM Fingerprints
auto-prune-posts-settings<!-- This is the form that shows the settings -->data-plugin-config-urldata-plugin-titledata-plugin-classauto_prune_posts_admin_obj