Excerpt Check Security & Risk Analysis

wordpress.org/plugins/excerpt-check

Prompts authors to add an excerpt before publishing or scheduling a WordPress post. Plugin Homepage

0 active installs v1.1.1 PHP 7.4+ WP 6.9+ Updated Mar 10, 2026
classic-editoreditorexcerptgutenbergpublishing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Excerpt Check Safe to Use in 2026?

Generally Safe

Score 100/100

Excerpt Check has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 24d ago
Risk Assessment

The "excerpt-check" plugin v1.1.1 demonstrates a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points, dangerous functions, or unsanitized taint flows is highly commendable. Furthermore, the commitment to using prepared statements for all SQL queries and proper output escaping for all outputs indicates robust secure coding practices.

However, the complete lack of any nonces or capability checks across the codebase, while not directly exploitable given the current attack surface, represents a potential area of concern for future extensibility or if new entry points were to be introduced. The vulnerability history being entirely clear also suggests a well-maintained or historically low-risk plugin. In conclusion, "excerpt-check" v1.1.1 appears very secure in its current state, with the primary minor weakness being the absence of any authentication/authorization mechanisms, which could become a risk if the plugin's functionality were to expand.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Excerpt Check Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Excerpt Check Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Attack Surface

Excerpt Check Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedexcerpt-check.php:69
actionenqueue_block_editor_assetsincludes\class-block-editor.php:39
actionadmin_enqueue_scriptsincludes\class-classic-editor.php:39
actionadmin_initincludes\class-settings.php:44
Maintenance & Trust

Excerpt Check Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 10, 2026
PHP min version7.4
Downloads221

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Excerpt Check Developer Profile

Tom McFarlin

3 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Excerpt Check

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/excerpt-check/assets/js/block-editor.js/wp-content/plugins/excerpt-check/assets/css/admin.css/wp-content/plugins/excerpt-check/assets/js/classic-editor.js
Script Paths
/wp-content/plugins/excerpt-check/assets/js/block-editor.js/wp-content/plugins/excerpt-check/assets/js/classic-editor.js
Version Parameters
excerpt-check/assets/js/block-editor.js?ver=excerpt-check/assets/css/admin.css?ver=excerpt-check/assets/js/classic-editor.js?ver=

HTML / DOM Fingerprints

JS Globals
excerptCheck
FAQ

Frequently Asked Questions about Excerpt Check