
LiveJournal Crossposter Security & Risk Analysis
wordpress.org/plugins/lj-xpAutomatically crossposts your WP entries to your LiveJournal or LJ-based clone.
Is LiveJournal Crossposter Safe to Use in 2026?
Generally Safe
Score 85/100LiveJournal Crossposter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lj-xp" v2.3.3 plugin exhibits a generally positive security posture with a notably small attack surface and no previously recorded vulnerabilities. The static analysis indicates no directly exposed AJAX handlers, REST API routes, shortcodes, or cron events that could be immediately exploited. Furthermore, the absence of critical or high-severity taint flows suggests that data handling within the plugin is likely to be robust against common injection attacks.
However, there are areas of concern that detract from an otherwise strong profile. The presence of the `create_function` dangerous function is a significant red flag, as it can lead to code execution vulnerabilities if used with untrusted input. While the majority of SQL queries use prepared statements, the remaining percentage and the lack of explicit capability checks or nonce checks on entry points (if any were present, despite the reported zero count) leave room for potential issues. The external HTTP request, though singular, should be monitored for potential vulnerabilities in the external service or if the URL is constructed dynamically.
Overall, "lj-xp" v2.3.3 appears to be a secure plugin based on its lack of historical vulnerabilities and limited attack surface. The code analysis does highlight a critical risk with `create_function` and a lack of fundamental security checks that warrant attention. Addressing these specific code-level concerns would further strengthen its security, but the absence of known exploits and generally good practices in SQL and output handling are positive indicators.
Key Concerns
- Use of dangerous function create_function
- No nonce checks on entry points
- No capability checks on entry points
- SQL queries not using prepared statements
- Output not properly escaped
LiveJournal Crossposter Security Vulnerabilities
LiveJournal Crossposter Release Timeline
LiveJournal Crossposter Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
LiveJournal Crossposter Attack Surface
WordPress Hooks 21
Maintenance & Trust
LiveJournal Crossposter Maintenance & Trust
Maintenance Signals
Community Trust
LiveJournal Crossposter Alternatives
LJ-XP-SW
crossposting-in-safe-way
LJ-XP-SW a plugin, that has the ability to crosspost a blog text to your LiveJournal (or LiveJournal-based clone) account in safe way.
Livejournal Crossposter Remix
livejournal-crossposter-remix
Automatically copies all posts to a LiveJournal or other LiveJournal-based blog (exclude text in shortcode [nocrosspost]smth[/nocrosspost] - buttons f …
Livejournal Crossposter Remix Rus translate
livejournal-crossposter-remix-rus
Пильгуй Анатолий
LJ comments import: reloaded
lj-comments-import-reloaded
Automatically synchronizes comments from Your LiveJournal blog with Your stand-alone Wordpress-based blog.
lj tag parser
lj-tag-parser
Replaces lj user, lj comm, and lj-cut tags with correct HTML code. This means your lj-cuts will behave like "more"s!
LiveJournal Crossposter Developer Profile
1 plugin · 200 total installs
How We Detect LiveJournal Crossposter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lj-xp/lj-xp.js/wp-content/plugins/lj-xp/lj-xp-admin.js/wp-content/plugins/lj-xp/lj-xp-frontend.js/wp-content/plugins/lj-xp/lj-xp.js/wp-content/plugins/lj-xp/lj-xp-admin.js/wp-content/plugins/lj-xp/lj-xp-frontend.jslj-xp/lj-xp.js?ver=lj-xp/lj-xp-admin.js?ver=lj-xp/lj-xp-frontend.js?ver=HTML / DOM Fingerprints
<!-- LJXP: Begin Post Options --><!-- LJXP: End Post Options -->data-ljxp-post-iddata-ljxp-actionljxp_admin_varsljxp_frontend_vars