Lightning Publisher for WordPress Security & Risk Analysis

wordpress.org/plugins/lightning-publisher

Lightning Publisher for WordPress allows you to offer previews of your blog posts and require a Lightning Network payment to release the rest.

10 active installs v0.1.8 PHP 5.6.0+ WP 4.0.0+ Updated Jul 14, 2018
bitcoinlightninglightning-chargemicropaymentspaywall
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lightning Publisher for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Lightning Publisher for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The lightning-publisher plugin exhibits a concerning security posture primarily due to its lack of authentication checks on all identified AJAX handlers. While the static analysis reveals no dangerous functions, SQL injection vulnerabilities, or unescaped output, the presence of four AJAX entry points that do not implement nonce or capability checks presents a significant risk. This means that any unauthenticated user could potentially trigger these AJAX actions, leading to unintended consequences depending on the functionality of these handlers.

The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a historically stable codebase. However, this does not negate the immediate risks identified in the current static analysis. The plugin's strengths lie in its adherence to secure coding practices regarding SQL queries and output escaping. Despite these strengths, the unprotected AJAX endpoints are a critical weakness that requires immediate attention to mitigate potential security breaches. The overall risk is moderate due to the critical nature of the unprotected entry points, despite the absence of historical vulnerabilities and other secure coding practices.

Key Concerns

  • AJAX handlers without authentication checks
  • All AJAX handlers lack authorization checks
Vulnerabilities
None known

Lightning Publisher for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Lightning Publisher for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface
4 unprotected

Lightning Publisher for WordPress Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_ln_publisher_invoicelightning-publisher.php:26
noprivwp_ajax_ln_publisher_invoicelightning-publisher.php:27
authwp_ajax_ln_publisher_tokenlightning-publisher.php:28
noprivwp_ajax_ln_publisher_tokenlightning-publisher.php:29
WordPress Hooks 4
actionwp_enqueue_scriptslightning-publisher.php:22
filterthe_contentlightning-publisher.php:23
actionadmin_initlightning-publisher.php:32
actionadmin_menulightning-publisher.php:33
Maintenance & Trust

Lightning Publisher for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 14, 2018
PHP min version5.6.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Lightning Publisher for WordPress Developer Profile

nadaviv

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lightning Publisher for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lightning-publisher/css/publisher.css/wp-content/plugins/lightning-publisher/js/publisher.js
Script Paths
/wp-content/plugins/lightning-publisher/js/publisher.js
Version Parameters
lightning-publisher/css/publisher.css?ver=lightning-publisher/js/publisher.js?ver=

HTML / DOM Fingerprints

CSS Classes
ln-publisher-paidln-publisher-payln-publisher-btn
Data Attributes
data-publisher-postid
JS Globals
LN_publisher
REST Endpoints
/wp-json/
Shortcode Output
<div class="ln-publisher-pay"><a class="ln-publisher-btn" href="#"<div class="ln-publisher-paid" id="paid">
FAQ

Frequently Asked Questions about Lightning Publisher for WordPress