
WP Tumblr Auto Publish Security & Risk Analysis
wordpress.org/plugins/auto-publish-tumblrPublish posts automatically to Tumblr.
Is WP Tumblr Auto Publish Safe to Use in 2026?
Generally Safe
Score 100/100WP Tumblr Auto Publish has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "auto-publish-tumblr" plugin v1.2.9 presents a mixed security posture. On the positive side, the plugin has a small attack surface, with only one AJAX handler and no exposed REST API routes, shortcodes, or cron events. Furthermore, it demonstrates a commitment to security by including a significant number of nonce and capability checks (8 and 2 respectively).
However, several concerning aspects warrant attention. The presence of the `unserialize` function is a significant risk, as it can be exploited for remote code execution if attacker-controlled data is unserialized. While taint analysis did not reveal critical or high severity unsanitized paths, the fact that 2 out of 4 analyzed flows had unsanitized paths is still a concern, even if currently at a lower severity. Additionally, the output escaping is only properly implemented for 30% of outputs, suggesting a potential for cross-site scripting (XSS) vulnerabilities. The plugin also makes 7 external HTTP requests, which could be a vector for various attacks if not handled securely.
The plugin's vulnerability history is a strong positive, with zero recorded CVEs. This indicates a historically stable and well-maintained codebase, or at least one that has not been publicly exploited. In conclusion, while the lack of known vulnerabilities and limited attack surface are strengths, the use of `unserialize` and the low percentage of properly escaped output represent notable weaknesses that could be exploited. The plugin's overall security is decent but could be significantly improved by addressing these specific issues.
Key Concerns
- Presence of unserialize function
- Low percentage of properly escaped output
- Unsanitized paths in taint analysis (2/4)
- Bundled library (Guzzle) - potential for outdated versions
WP Tumblr Auto Publish Security Vulnerabilities
WP Tumblr Auto Publish Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Tumblr Auto Publish Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
WP Tumblr Auto Publish Maintenance & Trust
Maintenance Signals
Community Trust
WP Tumblr Auto Publish Alternatives
Tumblr Importer
tumblr-importer
Imports a Tumblr blog into a WordPress blog.
Tumblr Widget
tumblr-widget-for-wordpress
Allows you to import a Tumblr into any widgetized area of a WordPress blog.
F2 Tumblr Widget
f2-tumblr-widget
This widget displays recent posts from a tumblr blog.
WooTumblog
woo-tumblog
Create a tumblr style blog using this plugin.
Avalicious!
avalicious
A WordPress plugin that integrates LiveJournal, Dreamwidth, and Tumblr user avatars in WordPress comments.
WP Tumblr Auto Publish Developer Profile
15 plugins · 142K total installs
How We Detect WP Tumblr Auto Publish
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-publish-tumblr/images/tb.png/wp-content/plugins/auto-publish-tumblr/js/notice.jsauto-publish-tumblr/css/style.css?ver=auto-publish-tumblr/js/notice.js?ver=HTML / DOM Fingerprints
tbap-settings-body<!-- WP Tumblr Auto Publish (VThis program is free software; you can redistribute it and/orThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+1 morexyz_script_tbap_var