
DJD Site Post Security & Risk Analysis
wordpress.org/plugins/djd-site-postWrite and edit a post at the front end without leaving your site. Supports guest posts.
Is DJD Site Post Safe to Use in 2026?
Generally Safe
Score 85/100DJD Site Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "djd-site-post" plugin, version 0.9.3, exhibits a mixed security posture. While it has no recorded vulnerabilities and utilizes prepared statements for SQL queries, several concerning code practices are evident. The presence of "create_function" is a significant risk as it is deprecated and can lead to arbitrary code execution if not handled with extreme care. Furthermore, a notable portion of output is not properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities, especially when user-supplied data is involved. The plugin also exposes two AJAX handlers without any authentication checks, creating a significant attack surface for unauthorized actions.
The taint analysis, while not revealing critical or high-severity issues, identified two flows with unsanitized paths. This, combined with the unescaped output and unprotected AJAX endpoints, suggests a potential for vulnerabilities where user input could be manipulated to achieve unintended results or compromise data. The absence of nonce checks on AJAX handlers is a missed opportunity to further secure these entry points. In conclusion, the plugin's lack of a vulnerability history is a positive sign, but the identified code quality issues, particularly the unprotected AJAX endpoints and inadequate output escaping, represent tangible security risks that require attention.
Key Concerns
- AJAX handlers without auth checks
- Unescaped output
- Dangerous function: create_function
- Flows with unsanitized paths
- Missing nonce checks on AJAX
DJD Site Post Security Vulnerabilities
DJD Site Post Release Timeline
DJD Site Post Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
DJD Site Post Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
DJD Site Post Maintenance & Trust
Maintenance Signals
Community Trust
DJD Site Post Alternatives
BP Site Post
bp-site-post
Designed to work with BuddyPress Group, Members Only and Friends posts this front end post editor comes with a wide range of features to allow you to …
Post From Site
post-from-site
Write a post without leaving your site!
Gravity Forms: Post Updates
gravity-forms-post-updates
Allows you to use Gravity Forms to update any post on the front end.
Stories for Ultimate Member
um-story-lite
Easy to use Frontend Journal for Ultimate Member. Give your users the option to add posts from the frontend
Sewn In Post Delete
sewn-in-post-delete
A very basic framework for deleting posts on the front end. Uses a nonce for security and checks capabilities to what a user has access to.
DJD Site Post Developer Profile
1 plugin · 100 total installs
How We Detect DJD Site Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/djd-site-post/css/display.css/wp-content/plugins/djd-site-post/js/display.js/wp-content/plugins/djd-site-post/js/script.js/wp-content/plugins/djd-site-post/js/display.js/wp-content/plugins/djd-site-post/js/script.jsdjd-site-post/css/display.css?ver=djd-site-post/js/display.js?ver=djd-site-post/js/script.js?ver=HTML / DOM Fingerprints
djd-site-postdjd-site-postdjd_site_post_ajax_object[djd-site-post]