
DJD Site Post Security & Risk Analysis
wordpress.org/plugins/djd-site-postWrite and edit a post at the front end without leaving your site. Supports guest posts.
Is DJD Site Post Safe to Use in 2026?
Generally Safe
Score 85/100DJD Site Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "djd-site-post" plugin, version 0.9.3, exhibits a mixed security posture. While it has no recorded vulnerabilities and utilizes prepared statements for SQL queries, several concerning code practices are evident. The presence of "create_function" is a significant risk as it is deprecated and can lead to arbitrary code execution if not handled with extreme care. Furthermore, a notable portion of output is not properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities, especially when user-supplied data is involved. The plugin also exposes two AJAX handlers without any authentication checks, creating a significant attack surface for unauthorized actions.
The taint analysis, while not revealing critical or high-severity issues, identified two flows with unsanitized paths. This, combined with the unescaped output and unprotected AJAX endpoints, suggests a potential for vulnerabilities where user input could be manipulated to achieve unintended results or compromise data. The absence of nonce checks on AJAX handlers is a missed opportunity to further secure these entry points. In conclusion, the plugin's lack of a vulnerability history is a positive sign, but the identified code quality issues, particularly the unprotected AJAX endpoints and inadequate output escaping, represent tangible security risks that require attention.
Key Concerns
- AJAX handlers without auth checks
- Unescaped output
- Dangerous function: create_function
- Flows with unsanitized paths
- Missing nonce checks on AJAX
DJD Site Post Security Vulnerabilities
DJD Site Post Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
DJD Site Post Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
DJD Site Post Maintenance & Trust
Maintenance Signals
Community Trust
DJD Site Post Alternatives
BP Site Post
bp-site-post
Designed to work with BuddyPress Group, Members Only and Friends posts this front end post editor comes with a wide range of features to allow you to …
Post From Site
post-from-site
Write a post without leaving your site!
Gravity Forms: Post Updates
gravity-forms-post-updates
Allows you to use Gravity Forms to update any post on the front end.
Sewn In Post Delete
sewn-in-post-delete
A very basic framework for deleting posts on the front end. Uses a nonce for security and checks capabilities to what a user has access to.
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration
wp-user-frontend
Create forms, guest posts, subscriptions, user directory, user registration, membership, frontend posts, profile builder, content restriction rules.
DJD Site Post Developer Profile
1 plugin · 100 total installs
How We Detect DJD Site Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/djd-site-post/css/display.css/wp-content/plugins/djd-site-post/js/display.js/wp-content/plugins/djd-site-post/js/script.js/wp-content/plugins/djd-site-post/js/display.js/wp-content/plugins/djd-site-post/js/script.jsdjd-site-post/css/display.css?ver=djd-site-post/js/display.js?ver=djd-site-post/js/script.js?ver=HTML / DOM Fingerprints
djd-site-postdjd-site-postdjd_site_post_ajax_object[djd-site-post]