
Obvious Post States Security & Risk Analysis
wordpress.org/plugins/obvious-post-statesMake the WordPress post state text (draft, pending, sticky, etc) stand out.
Is Obvious Post States Safe to Use in 2026?
Generally Safe
Score 85/100Obvious Post States has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "obvious-post-states" plugin version 1.0.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified vulnerabilities, CVEs, or taint flows is highly positive. Furthermore, the complete lack of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are excellent security practices. The plugin also demonstrates good protection for its identified entry points, with no unprotected AJAX handlers, REST API routes, shortcodes, or cron events. This indicates a diligent approach to securing the plugin's interaction points.
However, a significant concern arises from the output escaping analysis, where 100% of outputs are not properly escaped. This presents a potential Cross-Site Scripting (XSS) vulnerability, as unsanitized output displayed to users could be manipulated to inject malicious scripts. While the attack surface is zero, and the plugin has no recorded vulnerability history, this single unescaped output represents a clear and present risk. The lack of capability checks and nonce checks, while not directly evidenced as exploitable given the zero attack surface, could become a weakness if the attack surface were to expand in future versions without corresponding security checks. In conclusion, the plugin is largely secure with excellent foundational practices, but the unescaped output is a critical flaw that requires immediate attention.
Key Concerns
- Unescaped output
Obvious Post States Security Vulnerabilities
Obvious Post States Release Timeline
Obvious Post States Code Analysis
Output Escaping
Obvious Post States Attack Surface
WordPress Hooks 3
Maintenance & Trust
Obvious Post States Maintenance & Trust
Maintenance Signals
Community Trust
Obvious Post States Alternatives
Better Recent Drafts
better-recent-drafts
Displays an improved recent drafts widget on the dashboard
Sticky Header Effects for Elementor
sticky-header-effects-for-elementor
Create advanced Sticky Headers in Elementor Free or Pro with scroll effects, blur, shrink, hide on scroll & full responsive controls.
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu)
mystickymenu
Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌
Public Post Preview
public-post-preview
Allow anonymous users to preview a draft of a post before it is published.
Sticky Menu & Sticky Header
sticky-menu-or-anything-on-scroll
Sticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
Obvious Post States Developer Profile
2 plugins · 6K total installs
How We Detect Obvious Post States
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/obvious-post-states/obvious-post-states.css/wp-content/plugins/obvious-post-states/js/obvious-post-states.js/wp-content/plugins/obvious-post-states/js/obvious-post-states.jsobvious-post-states.css?ver=obvious-post-states.js?ver=HTML / DOM Fingerprints
post-state