
Old Post Message Security & Risk Analysis
wordpress.org/plugins/old-post-messageAutomatically displays messages on posts older than a specified period. Customizable via admin settings.
Is Old Post Message Safe to Use in 2026?
Generally Safe
Score 100/100Old Post Message has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "old-post-message" v1.2.5 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points (AJAX handlers, REST API routes, shortcodes, cron events) is a significant positive. Furthermore, the code demonstrates excellent practices with 100% of SQL queries using prepared statements and all identified output being properly escaped. The presence of a capability check also suggests some level of authorization is considered, even if not explicitly tied to every potential entry point (of which there are none).
Concerns are minimal, stemming primarily from the lack of nonce checks. While there are no apparent AJAX handlers or other exposed entry points to exploit this absence, it represents a missed security best practice that could become a vector if the plugin were to be extended or interact with other components in the future. The vulnerability history is completely clean, with no recorded CVEs, which indicates a well-maintained and likely secure plugin thus far. However, this clean history, combined with the lack of apparent attack surface, could also mean the plugin is very simple and has not been extensively tested or subjected to deep security scrutiny.
In conclusion, the plugin appears to be very secure at its current version. The development team has followed several key security principles. The main area for improvement would be the introduction of nonce checks for any potential future interfaces, even if none are currently exposed, to adhere to WordPress security standards more comprehensively. The absence of any identified vulnerabilities or exploitable code paths in the static analysis is a strong indicator of its current safety.
Key Concerns
- Missing nonce checks
Old Post Message Security Vulnerabilities
Old Post Message Code Analysis
Output Escaping
Old Post Message Attack Surface
WordPress Hooks 5
Maintenance & Trust
Old Post Message Maintenance & Trust
Maintenance Signals
Community Trust
Old Post Message Alternatives
Customize WordPress Emails and Alerts – Better Notifications for WP
bnfw
Supercharge your WordPress email notifications using a WYSIWYG editor and shortcodes. Default and new notifications available. Add-ons available.
Advanced Notifications
advanced-notifications
Advanced Notifications allows you to create beautiful custom notifications that appear on pages or posts of your choice.
Big Boom Alert Bar
big-boom-alert-bar
Adds an alert message to your site's front end, anywhere within the site layout
Old Post Notice
old-post-notice
Automatically display a customizable notice on posts older than a set number of days.
Responsive Attention Box
responsive-attention-box
Responsive Attention Box is a plugin that helps push important messages onto the screen
Old Post Message Developer Profile
2 plugins · 0 total installs
How We Detect Old Post Message
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/old-post-message/assets/css/frontend.css/wp-content/plugins/old-post-message/assets/js/frontend.jsHTML / DOM Fingerprints
data-old-post-message-enableddata-old-post-message-messagedata-old-post-message-icondata-old-post-message-bg-colordata-old-post-message-border-colordata-old-post-message-text-color