
Luzid Content Scheduler Security & Risk Analysis
wordpress.org/plugins/luzid-content-schedulerShow/hide frontend content blocks (banners, alerts, divs) with schedules, recurring rules and exceptions — via CSS class or shortcode.
Is Luzid Content Scheduler Safe to Use in 2026?
Generally Safe
Score 100/100Luzid Content Scheduler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "luzid-content-scheduler" v1.4.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, cron events, and file operations significantly reduces the plugin's attack surface. Furthermore, the code demonstrates good security practices by using prepared statements for all SQL queries and properly escaping a high percentage of its outputs. The presence of nonce and capability checks also indicates an effort to protect against common WordPress vulnerabilities. The plugin's vulnerability history being clean, with no known CVEs, further supports this positive assessment.
However, one significant concern is highlighted by the taint analysis: a single flow with an unsanitized path. While rated as "critical severity: 0" and "high severity: 0" within the taint analysis itself, the existence of such a flow, even if not currently exploitable or of low severity, warrants attention. This indicates a potential weakness where user-supplied data might not be adequately sanitized before being used in a sensitive operation, which could lead to unforeseen issues or be leveraged in conjunction with other vulnerabilities. The presence of two shortcodes also presents a potential entry point, though the static analysis indicates no unprotected ones.
In conclusion, "luzid-content-scheduler" v1.4.3 is commendably secure in many aspects, with robust handling of SQL and output, and a clean vulnerability history. The primary area for improvement lies in rigorously addressing the single identified unsanitized path flow to ensure complete security against potential path traversal or similar attacks, even if the current risk is assessed as low.
Key Concerns
- Flow with unsanitized path
Luzid Content Scheduler Security Vulnerabilities
Luzid Content Scheduler Code Analysis
Output Escaping
Data Flow Analysis
Luzid Content Scheduler Attack Surface
Shortcodes 2
WordPress Hooks 4
Maintenance & Trust
Luzid Content Scheduler Maintenance & Trust
Maintenance Signals
Community Trust
Luzid Content Scheduler Alternatives
Simple Certain Time to Show Content
simple-certain-time-to-show-content
At a time of your choosing, simply show or hide anything enclosed within a set of shortcodes.
Content Blocks (Custom Post Widget)
custom-post-widget
This plugin enables you to edit and display Content Blocks in a sidebar widget or using a shortcode.
Dynamic Month & Year into Posts
dynamic-month-year-into-posts
Automate SEO and content with dynamic shortcodes for dates, years, months, age calculations, seasons and countdowns in content, titles and meta.
Nelio Content – Editorial Calendar & Social Media Auto-Posting
nelio-content
Editorial calendar and social media auto-posting for WordPress. Plan content, schedule shares, and grow reach with powerful automations.
Post Content Shortcodes
post-content-shortcodes
Adds shortcodes to display the content of a post or a list of posts.
Luzid Content Scheduler Developer Profile
2 plugins · 0 total installs
How We Detect Luzid Content Scheduler
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/luzid-content-scheduler/lcs-admin.css/wp-content/plugins/luzid-content-scheduler/lcs-admin.js/wp-content/plugins/luzid-content-scheduler/lcs-frontend.css/wp-content/plugins/luzid-content-scheduler/lcs-frontend.js/wp-content/plugins/luzid-content-scheduler/lcs-admin.js/wp-content/plugins/luzid-content-scheduler/lcs-frontend.jsluzid-content-scheduler/lcs-admin.css?ver=luzid-content-scheduler/lcs-admin.js?ver=luzid-content-scheduler/lcs-frontend.css?ver=luzid-content-scheduler/lcs-frontend.js?ver=HTML / DOM Fingerprints
lcs-wraplcs-headerlcs-boxlcs-header__rowlcs-h1lcs-textlcs-text--mutedlcs-box--sub+2 more// phpcs:ignore WordPress.Security.NonceVerification.Recommended// phpcs:ignore WordPress.Security.ValidatedSanitizedInput.InputNotSanitizeddata-lcs-scheduler-idLCS_i18nLCS_scheduler_entriesLCS_scheduler_is_enLCS_scheduler_nonceLCS_scheduler_id_to_editLCS_scheduler_is_new_entry+8 more[lcs_next_event][luzid_content_scheduler]