
dotEPUB, a push-button cloud-based e-book maker Security & Risk Analysis
wordpress.org/plugins/dotepubThe dotEPUB plugin automatically adds a "Download as an e-book" button or link to your blog posts.
Is dotEPUB, a push-button cloud-based e-book maker Safe to Use in 2026?
Generally Safe
Score 85/100dotEPUB, a push-button cloud-based e-book maker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The dotepub plugin v1.1 exhibits a generally strong security posture, primarily due to the absence of known vulnerabilities and the use of prepared statements for all SQL queries. The static analysis reveals a minimal attack surface with only one shortcode and no AJAX handlers, REST API routes, or cron events, indicating a focused feature set. Furthermore, the lack of dangerous functions, file operations, and external HTTP requests reduces potential attack vectors.
However, there are areas for improvement. The low percentage of properly escaped output (5%) is a significant concern, as it indicates a high likelihood of cross-site scripting (XSS) vulnerabilities. While taint analysis did not reveal any unsanitized paths, the unescaped output presents a clear risk. The absence of nonce checks on the sole entry point (the shortcode) and a single capability check that might not cover all necessary scenarios also raise potential security questions. The plugin's clean vulnerability history is positive, suggesting good development practices or limited exposure, but it does not negate the risks identified in the static analysis.
In conclusion, dotepub v1.1 is a low-risk plugin with a commendable absence of known vulnerabilities and good SQL practices. The primary weakness lies in its output escaping, which could lead to XSS. Addressing this, along with ensuring proper authentication and authorization for its single entry point, would significantly enhance its security.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on entry point
- Limited capability checks on entry point
dotEPUB, a push-button cloud-based e-book maker Security Vulnerabilities
dotEPUB, a push-button cloud-based e-book maker Code Analysis
Output Escaping
dotEPUB, a push-button cloud-based e-book maker Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
dotEPUB, a push-button cloud-based e-book maker Maintenance & Trust
Maintenance Signals
Community Trust
dotEPUB, a push-button cloud-based e-book maker Alternatives
Allow ePUB and MOBI formats upload
allow-epub-and-mobi-formats-upload
WordPress does not allow upload ePUB and MOBI formats.
MPL-Publisher — Ebook & Audiobook Creator
mpl-publisher
MPL-Publisher 📚 creates an ebook, print-ready PDF book, EPUB for KDP, Flipbook, or Audiobook MP3 converting your WordPress posts.
Daily Free Kindle Books
daily-free-kindle-books
This plugin creates a sidebar widget that displays images of and links to free Kindle books for the day (updated daily). You can add your Amazon affil …
My Kindle Books
my-kindle-books
Show off your favourite Kindle books and make money doing it, by adding a book list page on your WordPress blog.
Post 2 epub
post-2-epub
Permite crear archivos en formato epub con las entradas publicadas en el sitio. Allows you to create epub format with the entries posted on the site.
dotEPUB, a push-button cloud-based e-book maker Developer Profile
1 plugin · 10 total installs
How We Detect dotEPUB, a push-button cloud-based e-book maker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dotepub/i/but62x20.png//dotepub.com/p/widget.phpHTML / DOM Fingerprints
dotEPUBremovedotEPUBbuttondotEPUBleftdotEPUBrightdotEPUBcenterdotEPUBimgdata-dotepublangdata-dotepublinksdata-dotepubtitledata-dotepubauthordotEPUBremove<span class="dotEPUBremove dotEPUBbutton">