
MyBB Cross-Postalicious Security & Risk Analysis
wordpress.org/plugins/mybb-cross-postaliciousAutomatically cross-post your Wordpress posts to MyBB, also contains a 'recent forum topics' widget.
Is MyBB Cross-Postalicious Safe to Use in 2026?
Generally Safe
Score 85/100MyBB Cross-Postalicious has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mybb-cross-postalicious" v1.1 plugin exhibits a mixed security posture. On the positive side, the absence of known CVEs and a history of no recorded vulnerabilities suggest a generally stable and well-maintained codebase. The static analysis also indicates a low attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authentication or permission checks. Furthermore, a high percentage of SQL queries utilize prepared statements, which is a strong security practice.
However, there are several concerning code signals that warrant attention. The presence of the `create_function` dangerous function is a significant risk, as it can be exploited for code injection if user-supplied data is passed to it without proper sanitization. The low percentage of properly escaped outputs (33%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website through improperly handled user input displayed on the front end. Additionally, the complete lack of nonce checks for any entry points is a critical oversight, leaving the plugin vulnerable to cross-site request forgery (CSRF) attacks. While no taint flows were detected, the other identified weaknesses present a considerable risk.
In conclusion, while the plugin benefits from a clean vulnerability history and a limited external attack surface, the identified code signals for `create_function`, insufficient output escaping, and a complete absence of nonce checks are serious security weaknesses. These issues significantly increase the risk of code injection and XSS vulnerabilities, and potentially CSRF attacks. The plugin requires immediate attention to address these critical code quality and security practice deficiencies.
Key Concerns
- Dangerous function detected: create_function
- Low percentage of properly escaped outputs
- No nonce checks detected
- Limited capability checks
MyBB Cross-Postalicious Security Vulnerabilities
MyBB Cross-Postalicious Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
MyBB Cross-Postalicious Attack Surface
WordPress Hooks 12
Maintenance & Trust
MyBB Cross-Postalicious Maintenance & Trust
Maintenance Signals
Community Trust
MyBB Cross-Postalicious Alternatives
Blog2Social: Social Media Auto Post & Scheduler
blog2social
Automatically share and schedule your WordPress content on top social platforms like Facebook, Instagram, LinkedIn, TikTok, and more.
Bit Social – Social Media Auto Poster and Scheduler
bit-social
Schedule WordPress posts to social media and auto share content across Facebook, Twitter (X), Instagram, Pinterest, TikTok, and LinkedIn.
BP Multiple Forum Post
bp-multiple-forum-post
Lets users cross-post a new bbpress forum topic in multiple BuddyPress group forums.
MassPost – Post, Share, Send to Several Websites
masspost
Publish once, distribute everywhere. MassPost securely pushes WordPress posts, all formats, images, categories etc to multiple sites.
bbPress
bbpress
bbPress is forum software for WordPress.
MyBB Cross-Postalicious Developer Profile
5 plugins · 140 total installs
How We Detect MyBB Cross-Postalicious
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mybb-cross-postalicious/css/mybbxp.css/wp-content/plugins/mybb-cross-postalicious/js/mybbxp.js/wp-content/plugins/mybb-cross-postalicious/js/mybbxp.jsmybb-cross-postalicious/css/mybbxp.css?ver=mybb-cross-postalicious/js/mybbxp.js?ver=HTML / DOM Fingerprints
mybbxp-meta-boxmybbxp_activemybbxp_mpidmybbxp_titlemybbxp_contentmybbxp_options