
Old Post Alert Security & Risk Analysis
wordpress.org/plugins/old-post-alertRemind your visitors about the age of old posts in the comment area - might cut down in irrelevant comments.
Is Old Post Alert Safe to Use in 2026?
Generally Safe
Score 85/100Old Post Alert has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, "old-post-alert" v1.2.0 exhibits a strong security posture in several key areas. The plugin has no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly minimizes its attack surface. Furthermore, the code signals indicate no dangerous functions, no raw SQL queries (all are prepared), no file operations, no external HTTP requests, and a complete absence of insecure bundled libraries. This suggests a development process that prioritizes secure coding practices and relies on WordPress's built-in security mechanisms.
However, a significant concern arises from the output escaping analysis. With one total output and 0% properly escaped, this indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from user input or external sources without proper sanitization and escaping is susceptible to malicious injection. While the taint analysis found no flows with unsanitized paths, this may be an artifact of the analysis scope or the limited attack surface. The absence of vulnerability history is positive, but it does not negate the identified risk in output escaping.
In conclusion, while "old-post-alert" v1.2.0 has commendable strengths in its minimal attack surface and secure handling of SQL and external interactions, the complete lack of output escaping presents a critical security weakness. This deficiency makes the plugin vulnerable to XSS attacks, which could lead to session hijacking, credential theft, or defacement of the website. Addressing this output escaping issue should be the immediate priority for improving the plugin's security.
Key Concerns
- Unescaped output detected
Old Post Alert Security Vulnerabilities
Old Post Alert Code Analysis
Output Escaping
Old Post Alert Attack Surface
WordPress Hooks 1
Maintenance & Trust
Old Post Alert Maintenance & Trust
Maintenance Signals
Community Trust
Old Post Alert Alternatives
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Remove noreferrer
remove-noreferrer
"Remove noreferrer" automatically removes rel="noreferrer" attribute from links on your website on-the-fly.
Disable Feeds and Comments
disable-rss-feeds-and-comments
This WordPress plugin, "Disable RSS Feeds and Comments," gives you the ability to turn off both the RSS feeds and comments on pages and/or p …
Move Comments
move-comments
This plugin allows you to move comments between posts in a simple and easy way by adding a page under (\'Move\') under the \'Comments\& …
Moving Contents
moving-contents
Supports the transfer of Contents between servers.
Old Post Alert Developer Profile
7 plugins · 2K total installs
How We Detect Old Post Alert
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
old_post_alert