Automated Editing Security & Risk Analysis

wordpress.org/plugins/automated-editing

If working with a lot of editors, who either don't know how to use WP or don't pay attention, this plugin helps you by adding an excerpt aut …

10 active installs v2.0.1 PHP + WP 3.1+ Updated Apr 9, 2016
auto-excerptautomated-editingautomated-excerptautomation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Automated Editing Safe to Use in 2026?

Generally Safe

Score 85/100

Automated Editing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "automated-editing" v2.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding database interactions by using prepared statements exclusively for its SQL queries and has no recorded vulnerability history, suggesting a generally stable and well-maintained codebase. The absence of external HTTP requests and bundled libraries also reduces potential attack vectors.

However, significant concerns arise from the static analysis. The plugin has zero nonce checks and zero capability checks, meaning that any functionality exposed, even if not directly through traditional entry points like AJAX or REST API, could potentially be accessed and manipulated by unauthenticated or unauthorized users. The taint analysis reveals two flows with unsanitized paths, which, while not flagged as critical or high severity, represent potential vulnerabilities if these paths lead to sensitive operations. Furthermore, a very low percentage (1%) of output escaping is deeply concerning, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities across the plugin's outputs.

While the lack of historical vulnerabilities is a positive indicator, it doesn't negate the immediate risks identified in the current codebase. The absence of authentication checks on potential entry points and the widespread lack of output escaping are critical weaknesses that need immediate attention to secure the plugin against common web attacks.

Key Concerns

  • No Nonce Checks
  • No Capability Checks
  • Very Low Output Escaping Rate
  • Unsanitized Paths in Taint Flows
Vulnerabilities
None known

Automated Editing Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Automated Editing Release Timeline

v2.0.1Current
v2.0
v1.9.2
v1.9.1
v1.9
v1.8.2
v1.8.1
v1.8
v1.7
v1.6
v1.5
v1.4
v1.3
v1.2
v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

Automated Editing Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
107
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

1% escaped108 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
file_template (class-lib/A5_DynamicFileClass.php:68)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Automated Editing Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
filterplugin_row_metaautomated-editing.php:56
filterplugin_action_linksautomated-editing.php:57
actionwp_insert_postautomated-editing.php:59
actionedit_attachmentautomated-editing.php:60
actionadd_attachmentautomated-editing.php:61
actionwp_before_admin_bar_renderautomated-editing.php:68
actionwp_insert_postautomated-editing.php:316
actionedit_attachmentautomated-editing.php:317
actionadd_attachmentautomated-editing.php:318
actioninitclass-lib/A5_DynamicFileClass.php:43
actiontemplate_redirectclass-lib/A5_DynamicFileClass.php:44
actionadmin_initclass-lib/AED_AdminClass.php:19
actioncontextual_helpclass-lib/AED_AdminClass.php:20
actionadmin_enqueue_scriptsclass-lib/AED_AdminClass.php:21
actionnetwork_admin_menuclass-lib/AED_AdminClass.php:25
actionadmin_menuclass-lib/AED_AdminClass.php:31
actionwp_insert_postclass-lib/AED_AdminClass.php:1715
actionedit_attachmentclass-lib/AED_AdminClass.php:1716
actionadd_attachmentclass-lib/AED_AdminClass.php:1717
Maintenance & Trust

Automated Editing Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 9, 2016
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Automated Editing Developer Profile

tepelstreel

11 plugins · 3K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Automated Editing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/automated-editing/class-lib/a5-excerptclass.css/wp-content/plugins/automated-editing/class-lib/a5-formfieldclass.css/wp-content/plugins/automated-editing/class-lib/a5-optionpageclass.css/wp-content/plugins/automated-editing/class-lib/a5-dynamicfileclass.css/wp-content/plugins/automated-editing/class-lib/aed-adminclass.css/wp-content/plugins/automated-editing/class-lib/a5-excerptclass.js/wp-content/plugins/automated-editing/class-lib/a5-formfieldclass.js/wp-content/plugins/automated-editing/class-lib/a5-optionpageclass.js+2 more
Script Paths
/wp-content/plugins/automated-editing/class-lib/a5-excerptclass.js/wp-content/plugins/automated-editing/class-lib/a5-formfieldclass.js/wp-content/plugins/automated-editing/class-lib/a5-optionpageclass.js/wp-content/plugins/automated-editing/class-lib/a5-dynamicfileclass.js/wp-content/plugins/automated-editing/class-lib/aed-adminclass.js
Version Parameters
automated-editing/class-lib/a5-excerptclass.css?ver=automated-editing/class-lib/a5-formfieldclass.css?ver=automated-editing/class-lib/a5-optionpageclass.css?ver=automated-editing/class-lib/a5-dynamicfileclass.css?ver=automated-editing/class-lib/aed-adminclass.css?ver=automated-editing/class-lib/a5-excerptclass.js?ver=automated-editing/class-lib/a5-formfieldclass.js?ver=automated-editing/class-lib/a5-optionpageclass.js?ver=automated-editing/class-lib/a5-dynamicfileclass.js?ver=automated-editing/class-lib/aed-adminclass.js?ver=

HTML / DOM Fingerprints

CSS Classes
aed-admin-settings
HTML Comments
Stop direct callCopyright 2011 - 2016 Stefan CrämerThis program is free softwareThis program is distributed in the hope that it will be useful+7 more
Data Attributes
data-multisitedata-readmoredata-thumbnaildata-exclude-from-more-tag
JS Globals
AED_PATHAED_BASE
FAQ

Frequently Asked Questions about Automated Editing