Mihdan: Public Post Preview Security & Risk Analysis

wordpress.org/plugins/mihdan-public-post-preview

Позволяет просматривать посты по красивому URL у черновиков в WordPress

10 active installs v1.9.12.1 PHP 5.6.20+ WP 4.9+ Updated Nov 25, 2022
cptcustom-post-typespostpostspublic-preview
85
A · Safe
CVEs total1
Unpatched0
Last CVEOct 17, 2022
Safety Verdict

Is Mihdan: Public Post Preview Safe to Use in 2026?

Generally Safe

Score 85/100

Mihdan: Public Post Preview has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Oct 17, 2022Updated 3yr ago
Risk Assessment

The 'mihdan-public-post-preview' plugin v1.9.12.1 exhibits a generally strong security posture based on static analysis. The absence of dangerous functions, proper output escaping for all identified outputs, and the use of prepared statements for all SQL queries are significant strengths. Furthermore, the presence of nonce and capability checks on its single AJAX handler, and the complete lack of REST API routes, shortcodes, or cron events, contribute to a very limited and secured attack surface. Taint analysis yielded no critical or high severity issues, indicating no immediate concerns with unsanitized data flows within the analyzed code.

However, the plugin's vulnerability history, specifically one known medium severity CVE related to 'Missing Authorization' and last patched in October 2022, represents a potential area of concern. While this vulnerability is marked as patched, the recurrence of this type of issue in the past suggests that authorization logic might be an area that requires ongoing vigilance or could be a recurring challenge for the plugin's developers. The plugin's current version appears to have addressed past vulnerabilities, but historical patterns of certain vulnerability types can indicate areas that are more prone to oversight.

In conclusion, 'mihdan-public-post-preview' v1.9.12.1 demonstrates good security practices in its current codebase, with a well-secured attack surface and robust code sanitization. The primary point of attention is the past medium severity vulnerability related to authorization, which, while seemingly patched, warrants a cautious approach. Users should ensure they are running the latest version to benefit from all security patches and monitor for any future updates.

Key Concerns

  • Past medium severity CVE (Missing Authorization)
Vulnerabilities
1 published

Mihdan: Public Post Preview Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

Mihdan: Public Post Preview <= 1.9.9 - Missing Authorization

Oct 17, 2022 Patched in 1.9.10 (463d)
Code Analysis
Analyzed Apr 16, 2026

Mihdan: Public Post Preview Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Attack Surface

Mihdan: Public Post Preview Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_mppp_togglesrc/Core.php:93
WordPress Hooks 9
actionafter_setup_thememihdan-public-post-preview.php:37
actionadd_meta_boxessrc/Core.php:91
actionadmin_enqueue_scriptssrc/Core.php:92
actiontransition_post_statussrc/Core.php:94
actionwp_insert_postsrc/Core.php:95
filterposts_resultssrc/Core.php:96
filterpreview_post_linksrc/Core.php:97
filterdisplay_post_statessrc/Core.php:98
actionwpsrc/Core.php:223
Maintenance & Trust

Mihdan: Public Post Preview Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 25, 2022
PHP min version5.6.20
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Mihdan: Public Post Preview Developer Profile

mihdan

12 plugins · 32K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
224 days
View full developer profile
Detection Fingerprints

How We Detect Mihdan: Public Post Preview

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mihdan-public-post-preview/admin/assets/js/app.js/wp-content/plugins/mihdan-public-post-preview/admin/assets/css/app.css
Script Paths
/wp-content/plugins/mihdan-public-post-preview/admin/assets/js/app.js
Version Parameters
mihdan-public-post-preview/admin/assets/js/app.js?ver=mihdan-public-post-preview/admin/assets/css/app.css?ver=

HTML / DOM Fingerprints

CSS Classes
public-post-preview-toggle
Data Attributes
data-mppp-toggledata-mppp-post-id
JS Globals
mppp
REST Endpoints
/wp-json/mppp/v1/toggle
FAQ

Frequently Asked Questions about Mihdan: Public Post Preview