
OptiPub Security & Risk Analysis
wordpress.org/plugins/optipubSync OptiPub content to WordPress with automated cron jobs and custom post types.
Is OptiPub Safe to Use in 2026?
Generally Safe
Score 100/100OptiPub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The optipub v1.0.14 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices in output escaping (99% properly escaped) and SQL query preparedness (79% using prepared statements), and has no recorded vulnerability history. This suggests a developer who is generally aware of security best practices regarding data output and database interaction. However, a significant concern arises from its attack surface. With 8 AJAX handlers, 7 of which lack authentication checks, and one REST API route without permission callbacks, there are multiple potential entry points for unauthorized access and manipulation. Furthermore, the presence of the `unserialize` function, a known dangerous function, introduces a risk of deserialization vulnerabilities if not handled with extreme care, especially given the lack of authorization on many AJAX endpoints. The taint analysis also reveals two high-severity flows with unsanitized paths, indicating potential for code execution or sensitive data compromise, which is exacerbated by the unprotected entry points. While the plugin has no known CVEs, the identified code signals and taint flows present latent risks that require attention.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Dangerous function: unserialize
- High severity taint flows with unsanitized paths
OptiPub Security Vulnerabilities
OptiPub Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
OptiPub Attack Surface
AJAX Handlers 8
REST API Routes 1
Shortcodes 1
WordPress Hooks 84
Maintenance & Trust
OptiPub Maintenance & Trust
Maintenance Signals
Community Trust
OptiPub Alternatives
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Custom Post Type Recent Entries Widget
cpt-recent-entries-widgets
Display a list of the most recent "Custom Post Type" entries in the WordPress widgets.
LabTheme Companion
labtheme-companion
The plugin generates multiple custom post types and number of exclusive widgets which are needed for wordpress theme developed by labtheme
Matcha Extra
matcha-extra
Used for adding extra features to WP Matcha Themes.
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
OptiPub Developer Profile
1 plugin · 0 total installs
How We Detect OptiPub
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/optipub/assets/css/optipub-public.css/wp-content/plugins/optipub/assets/js/optipub-public.js/wp-content/plugins/optipub/assets/css/optipub-admin.css/wp-content/plugins/optipub/assets/js/optipub-admin.js/wp-content/plugins/optipub/assets/js/optipub-public.js/wp-content/plugins/optipub/assets/js/optipub-admin.jsoptipub-public.css?ver=optipub-public.js?ver=optipub-admin.css?ver=optipub-admin.js?ver=HTML / DOM Fingerprints
optipub-content<!-- BEGIN OptiPub Content --><!-- END OptiPub Content --><!-- OptiPub Admin CSS --><!-- OptiPub Admin JS -->+2 moreoptipub_admin_ajax_urloptipub_public_settings/wp-json/optipub/v1/settings/wp-json/optipub/v1/publications/wp-json/optipub/v1/sync/wp-json/optipub/v1/sync-all/wp-json/optipub/v1/publication/