
Depublish Posts Security & Risk Analysis
wordpress.org/plugins/depublish-postsSchedule your posts or pages to expire at a given date.
Is Depublish Posts Safe to Use in 2026?
Generally Safe
Score 85/100Depublish Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'depublish-posts' plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and implementing nonce and capability checks for its identified entry points. The absence of file operations and external HTTP requests further reduces potential attack vectors. The taint analysis also reveals no critical or high severity flows, indicating that user input is not being mishandled in a way that could lead to immediate compromise.
However, a notable concern arises from the output escaping. With 50% of its outputs being unescaped, there is a tangible risk of Cross-Site Scripting (XSS) vulnerabilities. While the attack surface is small and protected, a successful XSS attack could still have significant consequences, such as session hijacking or defacement. The plugin's history of zero known CVEs is a positive indicator of past security diligence, but it does not negate the immediate risks identified in the current static analysis.
In conclusion, 'depublish-posts' v1.0.0 is a relatively secure plugin with a low overall attack surface and good adherence to fundamental security practices. The primary weakness lies in its output escaping, which needs to be addressed to mitigate XSS risks. Users should be aware of this potential vulnerability while benefiting from the plugin's generally robust security.
Key Concerns
- Unescaped output risk (XSS)
Depublish Posts Security Vulnerabilities
Depublish Posts Code Analysis
Output Escaping
Data Flow Analysis
Depublish Posts Attack Surface
WordPress Hooks 12
Scheduled Events 2
Maintenance & Trust
Depublish Posts Maintenance & Trust
Maintenance Signals
Community Trust
Depublish Posts Alternatives
Auto Post Expiry Manager
auto-post-expiry-manager
Automatically expire posts and custom post types at a specific date and time. Works with all public post types and uses a lightweight cron scheduler.
Post Calendar by Gelform
post-calendar-gelform
View your posts on a calendar and schedule posts with ease.
Comment Expirator
comment-expirator
Comment Expirator let's you close comments, pingbacks and trackbacks on your posts, pages and custom post types on an individual basis.
DishSoap
dishsoap
Automatically unpublish or unsticky a post on a specified date and time. Simple interface for ease of use.
Scheduled Posts Showcase
scheduled-posts-showcase
Display your scheduled and future posts on the frontend without generating 404 links. Show visitors what's coming next.
Depublish Posts Developer Profile
6 plugins · 111K total installs
How We Detect Depublish Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/depublish-posts/assets/wp-depublish-posts.css/wp-content/plugins/depublish-posts/assets/wp-depublish-posts.js/wp-content/plugins/depublish-posts/assets/wp-depublish-posts.js