
Nooz Security & Risk Analysis
wordpress.org/plugins/noozSimplified press release and media coverage management for websites.
Is Nooz Safe to Use in 2026?
Generally Safe
Score 92/100Nooz has a strong security track record. Known vulnerabilities have been patched promptly.
The "nooz" v1.7.2 plugin presents a generally good security posture, with a strong emphasis on secure coding practices. The complete absence of AJAX handlers and REST API routes without authentication checks, coupled with 100% prepared SQL statements and robust nonce and capability checks, indicates a conscious effort to protect against common web vulnerabilities. The high percentage of properly escaped output further strengthens this assessment.
However, a notable concern arises from the taint analysis, which identified one flow with unsanitized paths. While this did not escalate to a critical or high severity issue in static analysis, it represents a potential area for exploitation if not properly handled. The presence of a past medium severity Cross-Site Scripting (XSS) vulnerability, though currently patched, also warrants continued vigilance. This history suggests that input sanitization may have been a previous weakness, and while addressed, it highlights the importance of ongoing security audits.
In conclusion, "nooz" v1.7.2 demonstrates a solid foundation of secure development. The low attack surface and diligent use of security mechanisms are commendable. The primary areas for attention are the identified unsanitized path flow and the historical vulnerability. Addressing these proactively will ensure the plugin maintains its strong security standing and continues to protect users effectively.
Key Concerns
- Unsanitized path flow identified in taint analysis
- Past medium severity XSS vulnerability
Nooz Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Nooz <= 1.6.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Nooz Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Nooz Attack Surface
Shortcodes 3
WordPress Hooks 60
Maintenance & Trust
Nooz Maintenance & Trust
Maintenance Signals
Community Trust
Nooz Alternatives
Press, News, Events
press-news-events
Create custom post types for press releases, references to external news stories, and events.
Genesis Press Post Type
genesis-press-post-type
The Genesis Press Post Type plugin creates a "Press" custom post type and a display widget for adding media bookmarks to any child theme wri …
Press Release Newsroom
press-release-newsroom
Displays press releases via rss from PRWIREPRO's network on your pages or sidebar.
FileBird – WordPress Media Library Folders & File Manager
filebird
Organize thousands of WordPress media files in folders / categories with ease.
Real Media Library: Media Library Folder & File Manager
real-media-library-lite
Organize uploaded media in folders, collections and galleries: A file manager for WordPress. Media management made easy with Real Media Library! (Alte …
Nooz Developer Profile
2 plugins · 510 total installs
How We Detect Nooz
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nooz/css/main.css/wp-content/plugins/nooz/js/admin.js/wp-content/plugins/nooz/js/main.js/wp-content/plugins/nooz/js/admin.js/wp-content/plugins/nooz/js/main.jsnooz/css/main.css?ver=nooz/js/admin.js?ver=nooz/js/main.js?ver=HTML / DOM Fingerprints
nooz-release-itemnooz-coverage-itemnooz-shortcode-wrapper<!-- Generated by Nooz -->data-nooz-idnooz[nooz][nooz-release][nooz-coverage]