Live Blog WP – Easy WordPress Live Blogging Security & Risk Analysis

wordpress.org/plugins/live-blog-wp

Create a Gutenberg powered auto updating live blog and start live blogging directly within WordPress today.

10 active installs v1.0.5 PHP 7.0+ WP 5.0+ Updated Mar 8, 2021
live-bloglive-bloggingliveblog
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Live Blog WP – Easy WordPress Live Blogging Safe to Use in 2026?

Generally Safe

Score 85/100

Live Blog WP – Easy WordPress Live Blogging has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "live-blog-wp" plugin version 1.0.5 exhibits a concerning security posture due to its unprotected AJAX endpoints. While the static analysis reveals no dangerous functions, raw SQL queries, or file operations, the presence of two AJAX handlers without any authentication or capability checks presents a significant attack surface. This means that any unauthenticated user could potentially trigger these AJAX actions, leading to unintended consequences if not properly handled by the plugin's internal logic. The absence of taint analysis results is neutral, but the lack of nonce checks on these unprotected entry points is a critical oversight. The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator. However, this lack of history, combined with the identified architectural weaknesses in its entry points, suggests that the plugin might be relatively new or has not been subjected to extensive security scrutiny. In conclusion, while the plugin demonstrates good practices in SQL handling and output escaping, the unprotected AJAX endpoints are a major weakness that could be exploited, despite the absence of historical vulnerabilities.

Key Concerns

  • AJAX handlers without auth checks
  • Missing nonce checks on AJAX handlers
  • Large attack surface without auth
Vulnerabilities
None known

Live Blog WP – Easy WordPress Live Blogging Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Live Blog WP – Easy WordPress Live Blogging Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
36
146 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped182 total outputs
Attack Surface
2 unprotected

Live Blog WP – Easy WordPress Live Blogging Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_lbwp_get_postslive-blog-wp.php:132
authwp_ajax_lbwp_get_postslive-blog-wp.php:133
WordPress Hooks 10
actionplugins_loadedlive-blog-wp.php:66
actionadmin_noticeslive-blog-wp.php:103
actionadmin_noticeslive-blog-wp.php:109
actionadmin_noticeslive-blog-wp.php:115
actionacf/initlive-blog-wp.php:120
actionwp_enqueue_scriptslive-blog-wp.php:123
actioninitlive-blog-wp.php:126
actioninitlive-blog-wp.php:129
actioncustomize_registerlive-blog-wp.php:136
actionwp_headlive-blog-wp.php:137
Maintenance & Trust

Live Blog WP – Easy WordPress Live Blogging Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedMar 8, 2021
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Live Blog WP – Easy WordPress Live Blogging Developer Profile

liveblogwp

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Live Blog WP – Easy WordPress Live Blogging

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/live-blog-wp/blocks/live-blog.js
Script Paths
/wp-content/plugins/live-blog-wp/blocks/live-blog.js
Version Parameters
live-blog-wp/blocks/live-blog.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-wp-block
JS Globals
lbwp_live_blog
FAQ

Frequently Asked Questions about Live Blog WP – Easy WordPress Live Blogging