
Drewl Meta Preview Security & Risk Analysis
wordpress.org/plugins/meta-previewThe Drewl Meta Preview plugin will display how your WordPress content (post or page) will show on different social sharing platforms.
Is Drewl Meta Preview Safe to Use in 2026?
Generally Safe
Score 85/100Drewl Meta Preview has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The meta-preview plugin v1.0.0 presents a mixed security posture. On the positive side, it demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage (90%) of output escaping. The absence of known CVEs and bundled libraries further contributes to its perceived security. However, significant concerns arise from the identified attack surface. The plugin exposes one AJAX handler without any authentication or capability checks, creating a direct entry point for potential exploitation. While taint analysis did not reveal critical or high severity issues, the presence of one flow with an unsanitized path is a red flag that warrants further investigation, especially when combined with the unprotected AJAX endpoint.
The vulnerability history is a strong positive, with no recorded CVEs, suggesting a history of stable and secure code. This, coupled with the proper handling of SQL and most output, indicates that the developers are aware of common security pitfalls. Despite these strengths, the single unprotected AJAX handler is a critical weakness. This entry point, if it handles user-supplied data without sanitization or authorization, could be leveraged for various attacks. The plugin's overall security is good in terms of its handling of data and absence of past vulnerabilities, but the exposed, unprotected AJAX endpoint significantly lowers its security score and necessitates immediate attention.
Key Concerns
- AJAX handler without auth checks
- Flow with unsanitized paths
- Missing nonce checks on AJAX
Drewl Meta Preview Security Vulnerabilities
Drewl Meta Preview Release Timeline
Drewl Meta Preview Code Analysis
Output Escaping
Data Flow Analysis
Drewl Meta Preview Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Drewl Meta Preview Maintenance & Trust
Maintenance Signals
Community Trust
Drewl Meta Preview Alternatives
Meta Tag Manager
meta-tag-manager
Easily add and manage custom meta tags to various parts of your site or on individual posts, such as Yahoo and Google verification tags.
Dublin Core Metadata Generator
dublin-core-metadata-generator
A very lightweight plugin that adds the Dublin Core metadata to your WP website.
Meta Tags Generator
meta-tags-generator
Automatic generate meta tags. Let your WordPress site optimize with Search engine & Social sharing.
Lana SEO
lana-seo
Search Engine Optimization with automatic generation
WP Smart SEO
wp-smart-seo
Lightweight, powerful SEO for WordPress — control your meta titles, descriptions, Open Graph tags and more. No bloat, just results.
Drewl Meta Preview Developer Profile
1 plugin · 0 total installs
How We Detect Drewl Meta Preview
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/meta-preview/admin/css/style.css/wp-content/plugins/meta-preview/admin/js/script.js/wp-content/plugins/meta-preview/admin/images/favico-holder.png/wp-content/plugins/meta-preview/admin/js/script.jsdrewl-meta-previewHTML / DOM Fingerprints
drewl-meta-previewdrewl-mp-controlsdrewl-icondrewl-infodrewl-mp-preview<!-- og tags -->data-hashdrewl_meta_preview/wp-json/