
Blog Crosspost Security & Risk Analysis
wordpress.org/plugins/blog-crosspostAutomatically add posts from another WordPress website using a shortcode like [blogcrosspost url="example.com"]
Is Blog Crosspost Safe to Use in 2026?
Generally Safe
Score 92/100Blog Crosspost has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The blog-crosspost plugin v0.2.2 exhibits a generally strong security posture based on the static analysis provided. All identified code signals indicate good security practices, with 100% of SQL queries using prepared statements, all output properly escaped, and no dangerous functions, file operations, or external HTTP requests observed directly within the scope of the analysis. The plugin also lacks bundled libraries, mitigating risks associated with outdated dependencies. The attack surface is minimal, consisting solely of one shortcode with no apparent direct vulnerabilities detected through taint analysis.
However, a significant concern arises from the complete absence of nonce checks and capability checks. This indicates a lack of authorization and CSRF protection on potentially sensitive operations, even though no direct vulnerabilities were flagged in the static analysis. The presence of external HTTP requests, while not explicitly flagged as vulnerable, warrants attention as they can be a vector for various attacks if not properly validated and sanitized. The vulnerability history shows no known issues, which is positive, but the lack of any recorded vulnerabilities could also be due to limited historical auditing or the plugin's relative obscurity.
In conclusion, while the plugin demonstrates a good foundation in secure coding for SQL and output handling, the oversight in implementing nonce and capability checks represents a notable weakness. The minimal attack surface and lack of critical findings in static and taint analysis are strengths. The overall risk is moderate, primarily due to the potential for privilege escalation or unauthorized actions if the shortcode's functionality is susceptible to manipulation without proper authorization checks.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
Blog Crosspost Security Vulnerabilities
Blog Crosspost Release Timeline
Blog Crosspost Code Analysis
Output Escaping
Blog Crosspost Attack Surface
Shortcodes 1
Maintenance & Trust
Blog Crosspost Maintenance & Trust
Maintenance Signals
Community Trust
Blog Crosspost Alternatives
Moby Blog
moby-blog
Moby Blog - One APP for All Your Wordpress Blog! FREE! Are you a Blogger? Have a WordPress Blog? Turn it for free into a user friendly app for smartph …
BlogWired Gateway
blogwired-gateway
The official gateway plugin for the BlogWired application. Enables secure remote publishing from BlogWired to your WordPress site.
Backuply – Backup, Restore, Migrate and Clone
backuply
Backup, restores, and migration with Backuply are fairly simple with a wide range of storage options from Local Backups, FTP to cloud options like AWS …
BackWPup – WordPress Backup & Restore Plugin
backwpup
Create a complete WordPress backup easily. Schedule automatic backups, store securely, and restore effortlessly with the best WordPress backup plugin!
SiteOrigin Widgets Bundle
so-widgets-bundle
Essential elements for modern websites. Add buttons, sliders, heroes, maps, images, carousels, features, icons, more. Create dynamic pages easily.
Blog Crosspost Developer Profile
5 plugins · 3K total installs
How We Detect Blog Crosspost
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
blogcrosspost-pluginblog-crosspost-itemfeatured-image [blogcrosspost] data-blogcrosspost-id/wp-json/wp/v2/media/[blogcrosspost url="example.com"]