
OneClickPublish Security & Risk Analysis
wordpress.org/plugins/oneclickpublishThis is a very basic plugin to simple toggle the status of your posts between publish and post
Is OneClickPublish Safe to Use in 2026?
Generally Safe
Score 85/100OneClickPublish has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'oneclickpublish' v3.0 plugin exhibits a mixed security posture. On one hand, it demonstrates good practices such as using prepared statements for all SQL queries, implementing nonce checks, and capability checks. The absence of known CVEs and a clean vulnerability history suggest a generally well-maintained codebase. However, a significant concern arises from the presence of an unprotected AJAX handler, which represents a direct attack vector. The low percentage of properly escaped output (26%) also indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might not be adequately neutralized before being displayed to users.
The static analysis reveals a limited attack surface, with only one entry point identified. Crucially, this entry point is an AJAX handler that lacks proper authentication or authorization checks. While taint analysis shows no detected unsanitized flows, this could be due to the limited scope of the analysis or the specific types of data handled. The lack of critical or high severity issues in the historical vulnerability data is positive, but it does not negate the immediate risk posed by the unprotected AJAX handler and the potential for XSS due to insufficient output escaping.
In conclusion, while 'oneclickpublish' v3.0 has strengths in its SQL handling and use of WordPress security features like nonces and capability checks, the unprotected AJAX endpoint is a critical vulnerability that needs immediate attention. The poor output escaping further increases the risk of XSS attacks. Developers should prioritize securing the AJAX handler and improving output sanitization to mitigate these risks.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
OneClickPublish Security Vulnerabilities
OneClickPublish Code Analysis
Bundled Libraries
Output Escaping
OneClickPublish Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
OneClickPublish Maintenance & Trust
Maintenance Signals
Community Trust
OneClickPublish Alternatives
Extra Post Pages Menu
extra-posts-pages-menu
Adds extra and individual menus for all available post/page statuses like drafts, pending, trash including count of number of posts in each status.
Hide Drafts in Menus
hide-drafts-in-menus
Hide unpublished pages in your custom menus.
Pre-Publish Checklist
pre-publish-checklist
Easiest way to make sure your page or post is ready to go live
AMS Post And Page Duplicator
ams-post-and-page-duplicator
For creating copy of posts and pages.
Filter Admin Published Default
filter-admin-published-default
Enables all public post types (posts, pages, etc) in wp-admin to show the Published filter by default.
OneClickPublish Developer Profile
1 plugin · 20 total installs
How We Detect OneClickPublish
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oneclickpublish/js/jquery-1.9.js/wp-content/plugins/oneclickpublish/js/jquery.dataTables.js/wp-content/plugins/oneclickpublish/js/nk_script.js/wp-content/plugins/oneclickpublish/css/jquery.dataTables.css/wp-content/plugins/oneclickpublish/css/nk_style.css/wp-content/plugins/oneclickpublish/img/wpmini-blue.png/wp-content/plugins/oneclickpublish/js/jquery-1.9.js/wp-content/plugins/oneclickpublish/js/jquery.dataTables.js/wp-content/plugins/oneclickpublish/js/nk_script.jsHTML / DOM Fingerprints
nk-menu-admin-barnk-sub-menu-admin-bar-1nk-sub-menu-admin-bar-2nk-sub-menu-admin-bar-3nk-sub-menu-admin-bar-4id="nk-menu-admin-bar"id="nk-sub-menu-admin-bar-1"id="nk-sub-menu-admin-bar-2"id="nk-sub-menu-admin-bar-3"id="nk-sub-menu-admin-bar-4"nk_object