
AutoPromote Security & Risk Analysis
wordpress.org/plugins/autopromoteDynamically update sales information, banners, announcements, and promotions with ease across your website.
Is AutoPromote Safe to Use in 2026?
Generally Safe
Score 100/100AutoPromote has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Autopromote plugin v1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, and file operations are positive indicators. Furthermore, the plugin demonstrates good security practices by implementing nonce and capability checks, and the majority of output is properly escaped. The plugin's attack surface is also relatively small and appears to be protected.
However, the limited taint analysis results (0 flows analyzed) mean that while no issues were found, the depth of this analysis might not have been comprehensive enough to uncover potential vulnerabilities. The fact that 22% of output is not properly escaped presents a moderate risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if sensitive data is handled in these unescaped areas. The bundled Freemius library, if not kept up-to-date, could also pose a risk.
Overall, Autopromote v1.0 appears to be a well-developed plugin with sound security principles. The lack of any recorded vulnerabilities or CVEs is a significant strength. The primary areas for improvement are ensuring all output is properly escaped and monitoring the security of bundled libraries. The limited taint analysis warrants further investigation if resources permit.
Key Concerns
- Unescaped output detected
- Bundled Freemius v1.0 library
AutoPromote Security Vulnerabilities
AutoPromote Code Analysis
Bundled Libraries
Output Escaping
AutoPromote Attack Surface
REST API Routes 1
Shortcodes 8
WordPress Hooks 26
Maintenance & Trust
AutoPromote Maintenance & Trust
Maintenance Signals
Community Trust
AutoPromote Developer Profile
2 plugins · 0 total installs
How We Detect AutoPromote
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/autopromote/assets/css/public.cssautopromote/assets/css/public.css?ver=HTML / DOM Fingerprints
pixel-apfw-admin-columnspixel-apfw-public/wp-json/pixel-apfw/v1