
Mihdan: Public Post Preview Security & Risk Analysis
wordpress.org/plugins/mihdan-public-post-previewПозволяет просматривать посты по красивому URL у черновиков в WordPress
Is Mihdan: Public Post Preview Safe to Use in 2026?
Generally Safe
Score 85/100Mihdan: Public Post Preview has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'mihdan-public-post-preview' plugin v1.9.12.1 exhibits a generally strong security posture based on static analysis. The absence of dangerous functions, proper output escaping for all identified outputs, and the use of prepared statements for all SQL queries are significant strengths. Furthermore, the presence of nonce and capability checks on its single AJAX handler, and the complete lack of REST API routes, shortcodes, or cron events, contribute to a very limited and secured attack surface. Taint analysis yielded no critical or high severity issues, indicating no immediate concerns with unsanitized data flows within the analyzed code.
However, the plugin's vulnerability history, specifically one known medium severity CVE related to 'Missing Authorization' and last patched in October 2022, represents a potential area of concern. While this vulnerability is marked as patched, the recurrence of this type of issue in the past suggests that authorization logic might be an area that requires ongoing vigilance or could be a recurring challenge for the plugin's developers. The plugin's current version appears to have addressed past vulnerabilities, but historical patterns of certain vulnerability types can indicate areas that are more prone to oversight.
In conclusion, 'mihdan-public-post-preview' v1.9.12.1 demonstrates good security practices in its current codebase, with a well-secured attack surface and robust code sanitization. The primary point of attention is the past medium severity vulnerability related to authorization, which, while seemingly patched, warrants a cautious approach. Users should ensure they are running the latest version to benefit from all security patches and monitor for any future updates.
Key Concerns
- Past medium severity CVE (Missing Authorization)
Mihdan: Public Post Preview Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mihdan: Public Post Preview <= 1.9.9 - Missing Authorization
Mihdan: Public Post Preview Release Timeline
Mihdan: Public Post Preview Code Analysis
Output Escaping
Mihdan: Public Post Preview Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Mihdan: Public Post Preview Maintenance & Trust
Maintenance Signals
Community Trust
Mihdan: Public Post Preview Alternatives
Gravity Forms + Custom Post Types
gravity-forms-custom-post-types
Map your Gravity-Forms-generated posts to a custom post type and/or custom taxonomies.
MB Custom Post Types & Custom Taxonomies
mb-custom-post-type
Create and manage custom post types and custom taxonomies with an easy-to-use UI in WordPress.
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Post Types Unlimited
post-types-unlimited
Create unlimited custom post types and custom taxonomies.
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
Mihdan: Public Post Preview Developer Profile
12 plugins · 32K total installs
How We Detect Mihdan: Public Post Preview
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mihdan-public-post-preview/admin/assets/js/app.js/wp-content/plugins/mihdan-public-post-preview/admin/assets/css/app.css/wp-content/plugins/mihdan-public-post-preview/admin/assets/js/app.jsmihdan-public-post-preview/admin/assets/js/app.js?ver=mihdan-public-post-preview/admin/assets/css/app.css?ver=HTML / DOM Fingerprints
public-post-preview-toggledata-mppp-toggledata-mppp-post-idmppp/wp-json/mppp/v1/toggle