
Automatic Post Publishing Scheduler Security & Risk Analysis
wordpress.org/plugins/automatic-post-publishing-schedulerSchedule posts LIKE A BOSS!! Define time slots for publishing and forget about it.
Is Automatic Post Publishing Scheduler Safe to Use in 2026?
Generally Safe
Score 85/100Automatic Post Publishing Scheduler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "automatic-post-publishing-scheduler" v2.1.6 demonstrates a generally good security posture with several key strengths. Notably, there are no recorded vulnerabilities (CVEs) in its history, and the static analysis shows a complete absence of dangerous functions and file operations. All SQL queries are prepared, and the presence of numerous nonce and capability checks on its entry points (AJAX handlers) indicates a conscious effort to enforce authorization and prevent common attack vectors.
However, there are areas that warrant concern and could be improved. The most significant finding is a single flow with an unsanitized path identified during the taint analysis. While marked as not critical or high severity, unsanitized paths can still lead to path traversal vulnerabilities if not handled correctly by the application logic. Furthermore, the output escaping rate is only 20%, which is quite low. This suggests a significant number of outputs may be vulnerable to Cross-Site Scripting (XSS) attacks, especially if user-supplied data is involved in these unescaped outputs.
In conclusion, the plugin benefits from a clean vulnerability history and strong foundational security practices like prepared statements and authorization checks. The absence of critical vulnerabilities and the robust protection of its entry points are positive indicators. Nevertheless, the presence of an unsanitized path and the low output escaping rate represent tangible risks that should be addressed to further harden the plugin's security.
Key Concerns
- Flow with unsanitized path
- Low output escaping rate (20%)
Automatic Post Publishing Scheduler Security Vulnerabilities
Automatic Post Publishing Scheduler Code Analysis
Output Escaping
Data Flow Analysis
Automatic Post Publishing Scheduler Attack Surface
AJAX Handlers 5
WordPress Hooks 9
Maintenance & Trust
Automatic Post Publishing Scheduler Maintenance & Trust
Maintenance Signals
Community Trust
Automatic Post Publishing Scheduler Alternatives
Auto-Schedule Posts
auto-schedule-posts
Auto-Schedule Posts allows users to separate their writing schedule from their publishing schedule - write when you want and have posts publish at the …
Easy Bulk Date Editor
easy-bulk-date-editor
Bulk edit WordPress post dates safely and efficiently, now with filtering by category or author and paginated loading for better performance.
GT Post Approval
gt-post-approval
GT Post Approval adds "Approve/Reject" buttons visible just for administrators and editors in the Menage > Posts page.
WP Meta and Date Remover
wp-meta-and-date-remover
Remove meta author and date information from posts and pages. Hide from Humans and Search engines.SEO friendly and most advance plugin.
WP Admin UI Customize
wp-admin-ui-customize
Customize the management screen UI.
Automatic Post Publishing Scheduler Developer Profile
2 plugins · 40 total installs
How We Detect Automatic Post Publishing Scheduler
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/automatic-post-publishing-scheduler/css/scheduler.css/wp-content/plugins/automatic-post-publishing-scheduler/js/publishnow.js/wp-content/plugins/automatic-post-publishing-scheduler/js/scheduleroptions.js/wp-content/plugins/automatic-post-publishing-scheduler/js/publishnow.js/wp-content/plugins/automatic-post-publishing-scheduler/js/scheduleroptions.jsautomatic-post-publishing-scheduler/css/scheduler.css?ver=automatic-post-publishing-scheduler/js/publishnow.js?ver=automatic-post-publishing-scheduler/js/scheduleroptions.js?ver=automatic-post-publishing-scheduler/css/jquery-ui.min.css?ver=HTML / DOM Fingerprints
wrapupdatedoverlaypreloaderid="tabs"id="slots"id="weekdays"id="dates"id="general"id="set_time_slots"+2 more