
Drafty In Here Security & Risk Analysis
wordpress.org/plugins/drafty-in-hereGet email notifications of draft posts sitting in your WordPress Blog waiting to be published.
Is Drafty In Here Safe to Use in 2026?
Generally Safe
Score 85/100Drafty In Here has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "drafty-in-here" v1.2.0 exhibits a generally positive security posture, with no recorded vulnerabilities or CVEs, and a lack of complex attack surface. The static analysis reveals good practices such as 100% of SQL queries utilizing prepared statements, indicating a strong defense against SQL injection. File operations and external HTTP requests are absent, further reducing potential attack vectors. However, there are specific areas of concern. The presence of the `create_function` function is a significant risk, as it can be a vector for arbitrary code execution if user-supplied data is passed to it without proper sanitization. Additionally, the output escaping is only 43% proper, suggesting a risk of Cross-Site Scripting (XSS) vulnerabilities if untrusted data is displayed to users without adequate sanitization. The lack of any detected taint flows is encouraging, but this is often due to the limited attack surface and might not reflect the true potential risk given the other identified code quality issues.
Despite the absence of historical vulnerabilities, the identified code signals of `create_function` and insufficient output escaping necessitate caution. The plugin demonstrates strengths in its limited attack surface and secure SQL handling, but these are overshadowed by the potential for critical vulnerabilities if the identified issues are not addressed. A balanced conclusion is that while the plugin appears low-risk due to its simple functionality and lack of known issues, the presence of exploitable functions and unescaped output presents a clear and present danger that requires immediate attention.
Key Concerns
- Use of dangerous function create_function
- Low percentage of properly escaped output
- Missing nonce checks
Drafty In Here Security Vulnerabilities
Drafty In Here Code Analysis
Dangerous Functions Found
Output Escaping
Drafty In Here Attack Surface
WordPress Hooks 5
Maintenance & Trust
Drafty In Here Maintenance & Trust
Maintenance Signals
Community Trust
Drafty In Here Alternatives
Public Post Preview
public-post-preview
Allow anonymous users to preview a draft of a post before it is published.
The Paste
the-paste
Paste files and image data from clipboard and instantly upload them to the WordPress media library.
Media Focus Point
media-focus-point
The Media Focus Point Plugin ensures the key area of an image or video stays visible, regardless of resizing or layout changes.
Publish to Schedule
publish-to-schedule
Automate your WordPress post scheduling with Publish to Schedule. Set rules for days and times to publish posts automatically, saving you time and ens …
Share a Draft
shareadraft
Share private preview links to your drafts
Drafty In Here Developer Profile
1 plugin · 10 total installs
How We Detect Drafty In Here
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/drafty-in-here/