Consolety – Verified Content Publishing Network Security & Risk Analysis

wordpress.org/plugins/consolety

Exchange guest posts with verified publishers. Build quality backlinks through GSC-verified content collaboration.

60 active installs v5.0.3 PHP 8.0+ WP 5.8+ Updated Apr 6, 2026
backlinkscontent-publishingguest-postinglink-buildingseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Consolety – Verified Content Publishing Network Safe to Use in 2026?

Generally Safe

Score 100/100

Consolety – Verified Content Publishing Network has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The consolety v4.0.2 plugin exhibits a mixed security posture. While it has a clean vulnerability history with no recorded CVEs, indicating a potentially well-maintained codebase, the static analysis reveals significant concerns regarding its attack surface. A high number of AJAX handlers (8 total) are present, with a concerning majority (7 out of 8) lacking proper authentication checks. This creates a substantial entry point for attackers to interact with plugin functionality without authorization.

The code analysis also flags the use of the `unserialize` function, which can be dangerous if used with untrusted input, potentially leading to code execution vulnerabilities. While the taint analysis did not reveal any exploitable flows, the presence of `unserialize` without clear sanitization strategies on the input it processes remains a potential risk. The low percentage of properly escaped output further exacerbates this, suggesting that even if data is not directly manipulated, it could be displayed in a harmful manner.

In conclusion, the plugin's lack of historical vulnerabilities is a positive sign. However, the static analysis highlights critical weaknesses in its attack surface management and secure coding practices, particularly concerning unauthenticated AJAX endpoints and the use of `unserialize` with potentially unsanitized data. These factors significantly increase the risk of exploitation, despite the absence of known vulnerabilities.

Key Concerns

  • Unprotected AJAX handlers
  • Use of unserialize function
  • Low output escaping percentage
  • Low nonce check coverage
Vulnerabilities
None known

Consolety – Verified Content Publishing Network Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Consolety – Verified Content Publishing Network Release Timeline

v5.0.3Current
v3.1.0
v3.0.0
v2.1
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0
v1.1
v0.9.9.2
v0.9.9.1
v0.9.9
v0.9.8
v0.9.7
v0.9.6
v0.9.4
v0.9.3.1
v0.9.3
v0.9.2
Code Analysis
Analyzed Mar 16, 2026

Consolety – Verified Content Publishing Network Code Analysis

Dangerous Functions
1
Raw SQL Queries
4
9 prepared
Unescaped Output
57
12 escaped
Nonce Checks
2
Capability Checks
7
File Operations
0
External Requests
8
Bundled Libraries
0

Dangerous Functions Found

unserialize$site = unserialize($obj);classes\Entity\Site.php:33

SQL Query Safety

69% prepared13 total queries

Output Escaping

17% escaped69 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save_categories (classes\Ajax.php:28)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

Consolety – Verified Content Publishing Network Attack Surface

Entry Points8
Unprotected7

AJAX Handlers 8

authwp_ajax_flush_consoletyclasses\Ajax.php:18
authwp_ajax_consolety_reportclasses\Ajax.php:19
authwp_ajax_consolety_exportclasses\Ajax.php:20
authwp_ajax_consolety_export_singleclasses\Ajax.php:21
authwp_ajax_save_categoriesclasses\Ajax.php:22
noprivwp_ajax_consolety_reportclasses\Ajax.php:23
authwp_ajax_consolety_click_recordclasses\Ajax.php:24
noprivwp_ajax_consolety_click_recordclasses\Ajax.php:25
WordPress Hooks 19
actionadd_meta_boxesclasses\Admin\Posts\ConsoletyExportCheckbox.php:18
actionsave_postclasses\Admin\Posts\ConsoletyExportCheckbox.php:19
actionrest_api_initclasses\API.php:40
actionrest_api_initclasses\API.php:58
actionrest_api_initclasses\API.php:67
actionrest_api_initclasses\API.php:76
filterthe_contentclasses\Frontend\DisplayBlock.php:20
actionwp_headclasses\Frontend\SettingsDesignBlock.php:22
actionadmin_initclasses\Frontend\SettingsMainBlock.php:22
actionadmin_noticesclasses\Initialization.php:30
actionadmin_menuconsolety.php:47
actionwp_footerconsolety.php:48
actionadmin_enqueue_scriptsconsolety.php:49
actionplugins_loadedconsolety.php:50
actionplugins_loadedconsolety.php:51
actionadmin_initconsolety.php:52
actionpost_updatedconsolety.php:53
actiontransition_post_statusconsolety.php:55
actiondelete_postconsolety.php:57
Maintenance & Trust

Consolety – Verified Content Publishing Network Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 6, 2026
PHP min version8.0
Downloads16K

Community Trust

Rating100/100
Number of ratings8
Active installs60
Developer Profile

Consolety – Verified Content Publishing Network Developer Profile

Marijan Karajanov

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Consolety – Verified Content Publishing Network

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/consolety/css/admin.css/wp-content/plugins/consolety/js/admin.js
Version Parameters
consolety-admin?ver=

HTML / DOM Fingerprints

CSS Classes
consolety-styles-color
Data Attributes
data-default-color
JS Globals
consolety_reportconsolety_click_record
FAQ

Frequently Asked Questions about Consolety – Verified Content Publishing Network