
Cron Setup and Monitor – Get URL Cron Security & Risk Analysis
wordpress.org/plugins/get-url-cronManage cron jobs, monitor tasks, retry failures, and send email updates
Is Cron Setup and Monitor – Get URL Cron Safe to Use in 2026?
Generally Safe
Score 99/100Cron Setup and Monitor – Get URL Cron has a strong security track record. Known vulnerabilities have been patched promptly.
The 'get-url-cron' plugin v1.5.4 exhibits a generally good security posture in its static analysis, with a very low attack surface and a high percentage of properly escaped output. The absence of dangerous functions, a reliance on prepared statements for SQL queries, and the presence of nonce and capability checks in certain areas are positive indicators. Taint analysis also revealed no critical or high severity flows, suggesting a lack of easily exploitable vulnerabilities originating from user input that could lead to code execution or sensitive data exposure.
However, the plugin's vulnerability history is a significant concern. The presence of two known CVEs, specifically a high and a medium severity vulnerability, with the last one being relatively recent (February 2023), indicates a pattern of past security weaknesses. These historical vulnerabilities, categorized as Missing Authorization and Cross-Site Request Forgery (CSRF), point to potential issues with how user actions and data are handled, even if current static analysis doesn't immediately flag these specific flaws. The absence of currently unpatched vulnerabilities is positive, but the history suggests a need for vigilance and thorough auditing.
In conclusion, while the current version of 'get-url-cron' appears to have addressed past vulnerabilities and adheres to some good coding practices, the historical record warrants caution. Developers and users should be aware of the plugin's past security issues and ensure it's kept up-to-date. The lack of observable attack surface in static analysis is a strength, but the historical context of authorization and CSRF issues suggests potential blind spots or areas that may not be fully captured by static analysis alone.
Key Concerns
- Total known CVEs: 2
- High severity vulnerability history
- Medium severity vulnerability history
- Capability checks: 0
Cron Setup and Monitor – Get URL Cron Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Get URL Cron <= 1.4.7 - Missing Authorization via geturlcron_action_handle
Get URL Cron <= 1.4.7 - Cross-Site Request Forgery via geturlcron_action_handle
Cron Setup and Monitor – Get URL Cron Code Analysis
Output Escaping
Data Flow Analysis
Cron Setup and Monitor – Get URL Cron Attack Surface
WordPress Hooks 5
Maintenance & Trust
Cron Setup and Monitor – Get URL Cron Maintenance & Trust
Maintenance Signals
Community Trust
Cron Setup and Monitor – Get URL Cron Alternatives
Vigilant Healthchecks
vigilant-healthchecks
A WordPress plugin that provides healthchecks to your WordPress site that integrate seamlessly with Vigilant (https://govigilant.io).
Action Scheduler
action-scheduler
Action Scheduler - Job Queue for WordPress
WP-Cron Status Checker
wp-cron-status-checker
If WP-Cron runs important things for you, you better make sure WP-Cron always runs!
Health Endpoint
health-endpoint
Creates a /health endpoint that returns a 200 OK HTTP status code while WordPress is performing correctly.
SEO Repair Kit – AI Chatbot, Schema Manager, SEO Content Monitoring, GSC Integration, Keyword & Rank Tracking
seo-repair-kit
The ultimate WordPress plugin for SEO automation - from link fixing to AI-powered schema generation and chatbot support.
Cron Setup and Monitor – Get URL Cron Developer Profile
5 plugins · 17K total installs
How We Detect Cron Setup and Monitor – Get URL Cron
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/get-url-cron/geturlcron.phpget-url-cron/geturlcron.php?ver=geturlcron_version=1.5.4HTML / DOM Fingerprints
geturlcron-emailadrgeturlcron-mailonlyfailgeturlcron-timeoutgeturlcron-dellog-daysgeturlcron-maxno-cronjobsgeturlcron-uninstall-deleteall+6 more