AutoPromote Security & Risk Analysis

wordpress.org/plugins/autopromote

Dynamically update sales information, banners, announcements, and promotions with ease across your website.

0 active installs v1.0 PHP 7.4+ WP 6.6+ Updated Jun 25, 2025
campaign-managermarketing-managerpromotion-schedulersales-calendarsales-planner
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AutoPromote Safe to Use in 2026?

Generally Safe

Score 100/100

AutoPromote has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The Autopromote plugin v1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, and file operations are positive indicators. Furthermore, the plugin demonstrates good security practices by implementing nonce and capability checks, and the majority of output is properly escaped. The plugin's attack surface is also relatively small and appears to be protected.

However, the limited taint analysis results (0 flows analyzed) mean that while no issues were found, the depth of this analysis might not have been comprehensive enough to uncover potential vulnerabilities. The fact that 22% of output is not properly escaped presents a moderate risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if sensitive data is handled in these unescaped areas. The bundled Freemius library, if not kept up-to-date, could also pose a risk.

Overall, Autopromote v1.0 appears to be a well-developed plugin with sound security principles. The lack of any recorded vulnerabilities or CVEs is a significant strength. The primary areas for improvement are ensuring all output is properly escaped and monitoring the security of bundled libraries. The limited taint analysis warrants further investigation if resources permit.

Key Concerns

  • Unescaped output detected
  • Bundled Freemius v1.0 library
Vulnerabilities
None known

AutoPromote Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AutoPromote Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
94 escaped
Nonce Checks
3
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

78% escaped120 total outputs
Attack Surface

AutoPromote Attack Surface

Entry Points9
Unprotected0

REST API Routes 1

GET/wp-json/pixel-apfw/v1/promotion-datesincludes\rest-api.php:17

Shortcodes 8

[pixel_apfw_promotion_name] includes\shortcodes.php:210
[pixel_apfw_promotion_description] includes\shortcodes.php:240
[pixel_apfw_promotion_image] includes\shortcodes.php:270
[pixel_apfw_promotion_coupon_code] includes\shortcodes.php:318
[pixel_apfw_promotion_discount_amount] includes\shortcodes.php:381
[pixel_apfw_promotion_date] includes\shortcodes.php:436
[pixel_apfw_promotion_start_date] includes\shortcodes.php:446
[pixel_apfw_promotion_end_date] includes\shortcodes.php:457
WordPress Hooks 26
actionafter_uninstallautopromote.php:66
actioninitautopromote.php:156
actionadmin_menuautopromote.php:157
actionadmin_enqueue_scriptsautopromote.php:158
actionwp_enqueue_scriptsautopromote.php:159
actionplugins_loadedautopromote.php:262
filtermanage_pixel_apfw_promotion_posts_columnsincludes\admin-columns.php:32
filtermanage_edit-pixel_apfw_promotion_sortable_columnsincludes\admin-columns.php:46
actionpre_get_postsincludes\admin-columns.php:76
actionmanage_pixel_apfw_promotion_posts_custom_columnincludes\admin-columns.php:129
filterviews_edit-pixel_apfw_promotionincludes\admin-columns.php:242
filterparent_fileincludes\admin-menu.php:106
actionadmin_initincludes\admin-settings.php:130
actionadmin_enqueue_scriptsincludes\admin-settings.php:522
actionadd_meta_boxes_pixel_apfw_promotionincludes\metaboxes.php:31
actionadmin_noticesincludes\metaboxes.php:370
actionsave_post_pixel_apfw_promotionincludes\metaboxes.php:540
actionsave_post_pixel_apfw_promotionincludes\metaboxes.php:558
filterredirect_post_locationincludes\metaboxes.php:587
actionadmin_noticesincludes\metaboxes.php:649
actionadmin_enqueue_scriptsincludes\metaboxes.php:739
actionadmin_noticesincludes\metaboxes.php:780
filterget_edit_post_linkincludes\metaboxes.php:823
actionrest_api_initincludes\rest-api.php:37
actionsave_post_pixel_apfw_promotionincludes\shortcodes.php:162
actiondelete_postincludes\shortcodes.php:169
Maintenance & Trust

AutoPromote Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 25, 2025
PHP min version7.4
Downloads290

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AutoPromote Developer Profile

PixelPlugins

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AutoPromote

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/autopromote/assets/css/public.css
Version Parameters
autopromote/assets/css/public.css?ver=

HTML / DOM Fingerprints

CSS Classes
pixel-apfw-admin-columnspixel-apfw-public
REST Endpoints
/wp-json/pixel-apfw/v1
FAQ

Frequently Asked Questions about AutoPromote