
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media Security & Risk Analysis
wordpress.org/plugins/evergreen-content-posterAutomatically share your best WordPress content (posts/pages/custom post types) to X (Twitter), Mastodon, Facebook, Instagram, Pinterest, LinkedIn and …
Is Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media Safe to Use in 2026?
Generally Safe
Score 96/100Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media has a strong security track record. Known vulnerabilities have been patched promptly.
The Evergreen Content Poster plugin exhibits a mixed security posture. On one hand, it demonstrates good practices in areas like SQL query preparation (87% prepared) and output escaping (97% escaped), along with a substantial number of capability checks (73) and nonce checks (44). The absence of critical or high-severity taint analysis findings is also a positive indicator. However, a significant concern arises from the attack surface, particularly the 9 AJAX handlers that lack authentication checks. This represents a direct pathway for potential unauthorized actions if not properly secured by WordPress's default user roles.
The vulnerability history is a more concerning aspect. While there are no currently unpatched CVEs, the plugin has a history of 6 medium-severity vulnerabilities, including Cross-Site Request Forgery (CSRF), Missing Authorization, and Cross-Site Scripting (XSS). The pattern of these past vulnerabilities suggests a recurring need for careful input validation and authorization checks. The most recent vulnerability was in July 2025, which, if the current date is prior to that, indicates that the latest version (1.4.8) may have addressed past issues, but the history itself warrants caution.
In conclusion, while the plugin has strengths in its code hygiene for SQL and output, the presence of unprotected AJAX handlers and a history of medium-severity vulnerabilities necessitates a cautious approach. Users should ensure they are using the latest version of the plugin to benefit from any patches applied since the last reported vulnerability. Further investigation into the specific nature of the past vulnerabilities and the functionality of the unprotected AJAX handlers would be advisable for a complete risk assessment.
Key Concerns
- 9 AJAX handlers without auth checks
- 6 medium severity CVEs in history
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Evergreen Content Poster <= 1.4.5 - Cross-Site Request Forgery
Evergreen Content Poster <= 1.4.5 - Missing Authorization
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
Evergreen Content Poster <= 1.4.2 - Missing Authorization
Evergreen Content Poster <= 1.4.1 - Reflected Cross-Site Scripting
Evergreen Content Poster <= 1.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media Attack Surface
AJAX Handlers 40
WordPress Hooks 26
Scheduled Events 3
Maintenance & Trust
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media Maintenance & Trust
Maintenance Signals
Community Trust
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media Alternatives
Post to Social Media – WordPress to Hootsuite
wp-to-hootsuite
Automatically share WordPress Pages, Posts or Custom Post Types to Facebook, Twitter and LinkedIn using your Hootsuite (hootsuite.com) account.
Auto Post to Social Media from Social Champ
auto-post-to-social-media-wp-to-social-champ
It sends WP Pages, Posts or Custom Post Types to your Social Champ (SocialChamp.com) account for immediate or scheduled publishing to social networks.
PR-Gateway Connect
pr-gateway-connect
Dear user,
Post Bridge Social Poster
post-bridge-social-poster
Unofficial Plugin to automatically post WordPress Content to Social Media using your Post Bridge (post-bridge.com) account.
Revive Social – Social Media Auto Post and Scheduling Automation Plugin
tweet-old-post
Automatically share your WordPress posts on multiple social networks like Facebook, X (Twitter), LinkedIn, Instagram and more.
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media Developer Profile
1 plugin · 100 total installs
How We Detect Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/evergreen-content-poster/assets/css/bootstrap.min.css/wp-content/plugins/evergreen-content-poster/assets/css/ecp-global.css/wp-content/plugins/evergreen-content-poster/assets/css/ecp-settings.css/wp-content/plugins/evergreen-content-poster/assets/css/jquery-ui.min.css/wp-content/plugins/evergreen-content-poster/assets/js/bootstrap.min.js/wp-content/plugins/evergreen-content-poster/assets/js/ecp-global.js/wp-content/plugins/evergreen-content-poster/assets/js/ecp-settings.js/wp-content/plugins/evergreen-content-poster/assets/js/jquery-ui.min.js+16 more/wp-content/plugins/evergreen-content-poster/assets/js/bootstrap.min.js/wp-content/plugins/evergreen-content-poster/assets/js/ecp-global.js/wp-content/plugins/evergreen-content-poster/assets/js/ecp-settings.js/wp-content/plugins/evergreen-content-poster/assets/js/jquery-ui.min.js/wp-content/plugins/evergreen-content-poster/assets/js/jquery.min.js/wp-content/plugins/evergreen-content-poster/assets/js/jquery.validate.min.js+10 moreevergreen-content-poster/assets/css/bootstrap.min.css?ver=evergreen-content-poster/assets/css/ecp-global.css?ver=evergreen-content-poster/assets/css/ecp-settings.css?ver=evergreen-content-poster/assets/css/jquery-ui.min.css?ver=evergreen-content-poster/assets/js/bootstrap.min.js?ver=evergreen-content-poster/assets/js/ecp-global.js?ver=evergreen-content-poster/assets/js/ecp-settings.js?ver=evergreen-content-poster/assets/js/jquery-ui.min.js?ver=evergreen-content-poster/assets/js/jquery.min.js?ver=evergreen-content-poster/assets/js/jquery.validate.min.js?ver=evergreen-content-poster/assets/js/post-buffer.js?ver=evergreen-content-poster/assets/js/tinymce/tinymce.min.js?ver=evergreen-content-poster/css/bootstrap.min.css?ver=evergreen-content-poster/css/ecp-global.css?ver=evergreen-content-poster/css/ecp-settings.css?ver=evergreen-content-poster/css/jquery-ui.min.css?ver=evergreen-content-poster/js/bootstrap.min.js?ver=evergreen-content-poster/js/ecp-global.js?ver=evergreen-content-poster/js/ecp-settings.js?ver=evergreen-content-poster/js/jquery-ui.min.js?ver=evergreen-content-poster/js/jquery.min.js?ver=evergreen-content-poster/js/jquery.validate.min.js?ver=evergreen-content-poster/js/post-buffer.js?ver=evergreen-content-poster/js/tinymce/tinymce.min.js?ver=HTML / DOM Fingerprints
ecp-global-settings-sectionecp-global-settings-wrapperecp-network-post-limit-settingecp-global-settings-input-widthecp-global-settings-itemecp-global-settings-item-labelecp-global-settings-item-inputecp-global-settings-section-description+61 more<!-- Main Content --><!-- Settings Page --><!-- Content Buffer Log --><!-- Add/Edit Profile -->+7 moredata-ecp-profile-iddata-toggle="tooltip"data-placement="top"title="View Post Buffer Log"title="Edit Profile"title="Delete Profile"+1 moreecp_global_settingspost_buffer_settingsecp_settings_varstinymce_settings