KV Front-end Post Submission Security & Risk Analysis

wordpress.org/plugins/kv-front-post-submission

Front post Submission is a simple plug-in to submit WordPress posts from the front end.

10 active installs v1.2.1 PHP + WP 3.7+ Updated Apr 21, 2017
front-end-postpagespost-submit
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is KV Front-end Post Submission Safe to Use in 2026?

Generally Safe

Score 85/100

KV Front-end Post Submission has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The kv-front-post-submission plugin v1.2.1 exhibits a generally good security posture regarding SQL injection and external requests, with all SQL queries utilizing prepared statements and only one external HTTP request noted. The absence of known CVEs and a clean vulnerability history further contribute to a positive impression. However, the analysis reveals significant concerns in output escaping and authorization checks. A concerning 0% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the lack of any capability checks or nonce checks on its single shortcode entry point means that any user, regardless of their role or permissions, could potentially trigger its functionality, leading to unauthorized actions or information disclosure. The limited attack surface is a mitigating factor, but the lack of fundamental security practices in handling output and user permissions is a critical weakness.

Key Concerns

  • Output escaping is not performed
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

KV Front-end Post Submission Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

KV Front-end Post Submission Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

0% escaped5 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
kv_front_post_creation (kv_front_post.php:256)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

KV Front-end Post Submission Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[kv_submit_post] kv_front_post.php:254
WordPress Hooks 5
actionadmin_menukv_front_post.php:25
actionadmin_print_styleskv_front_post.php:125
actionadmin_menukv_front_post.php:134
actionadmin_initkv_front_post.php:138
actionadmin_initkv_front_post.php:232
Maintenance & Trust

KV Front-end Post Submission Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedApr 21, 2017
PHP min version
Downloads3K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

KV Front-end Post Submission Developer Profile

kvvaradha

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect KV Front-end Post Submission

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kv-front-post-submission/kv_admi_style.css
Version Parameters
kv_admi_style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wrapicon32postboxhndleinsideform-tablecolumns-2metabox-holder+2 more
Data Attributes
data-name="kv_post_types"data-name="kv_media_button"data-name="kv_richtext_editor"data-name="kv_post_status"name="kv_richtext_editor"name="kv_media_button"+1 more
FAQ

Frequently Asked Questions about KV Front-end Post Submission