
Expiring Posts Security & Risk Analysis
wordpress.org/plugins/expiring-postsThis plugin adds functionality to expire a post on a given date.
Is Expiring Posts Safe to Use in 2026?
Generally Safe
Score 85/100Expiring Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "expiring-posts" plugin v1.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The complete absence of known CVEs and the plugin's adherence to secure coding practices like prepared statements for SQL queries, nonce checks, and capability checks are highly commendable. The limited attack surface with no unprotected entry points further enhances its security.
However, a minor concern arises from the output escaping, where 25% of the outputs are not properly escaped. While this doesn't indicate a critical vulnerability in this specific analysis, it represents a potential area for XSS (Cross-Site Scripting) vulnerabilities if user-supplied data is involved in those unescaped outputs. This is a common oversight that can be exploited in certain contexts, even with an otherwise secure plugin.
Overall, the plugin demonstrates a robust commitment to security, with no critical or high-risk findings in the code analysis. The vulnerability history is clean, suggesting consistent secure development. The only area for improvement is ensuring 100% output escaping to mitigate any potential future risks, even if none are currently evident.
Key Concerns
- Unescaped outputs detected
Expiring Posts Security Vulnerabilities
Expiring Posts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Expiring Posts Attack Surface
WordPress Hooks 8
Scheduled Events 1
Maintenance & Trust
Expiring Posts Maintenance & Trust
Maintenance Signals
Community Trust
Expiring Posts Alternatives
WP Post Expires
wp-post-expires
Plugin adds post expires time after which will be performed actions: add prefix to title, move to drafts or trash.
Content Scheduler
content-scheduler
Schedule content to automatically expire and change at a certain time, and notify people of expiration.
VA Simple Expires
va-simple-expires
This is the fork of Simple Expires created by Mr. abmcr. Simple plugin which can set up the term of validity.
Simple Expires
simple-expires
Enable Posts and Pages to automatically expire and change at a certain time, and provide notification of expiration.
Post Expiring
post-expiring
Expire post by set the date of expiring
Expiring Posts Developer Profile
2 plugins · 21K total installs
How We Detect Expiring Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/expiring-posts/inc/js/expiring-posts.js/wp-content/plugins/expiring-posts/inc/css/expiring-posts.cssexpiring-posts/inc/js/expiring-posts.js?ver=expiring-posts/inc/css/expiring-posts.css?ver=HTML / DOM Fingerprints
expiryname="exp-aa"name="exp-mm"name="exp-jj"name="exp-hh"name="exp-mn"name="exp-ss"+3 moreAdminExpiringPosts