OrganicStack Publisher Security & Risk Analysis

wordpress.org/plugins/organicstack-publisher

Clean API for automated WordPress content publishing with AI integration support. Designed for use with OrganicStack.

10 active installs v1.0.8 PHP 7.4+ WP 5.0+ Updated Apr 13, 2026
aiauto-publishautomationblog-automationscheduling
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OrganicStack Publisher Safe to Use in 2026?

Generally Safe

Score 100/100

OrganicStack Publisher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "organicstack-publisher" v1.0.8 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, and vulnerabilities in the vulnerability history are positive indicators. The fact that all SQL queries use prepared statements and all output is properly escaped demonstrates adherence to fundamental WordPress security best practices. The plugin also demonstrates an awareness of security by implementing nonce checks and capability checks, although the limited number of these checks might warrant further investigation in a more in-depth analysis. The plugin's vulnerability history being completely clean suggests a low likelihood of previously exploited weaknesses.

Key Concerns

  • REST API routes without permission callbacks
  • Low number of capability checks relative to entry points
  • Low number of nonce checks relative to entry points
Vulnerabilities
None known

OrganicStack Publisher Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

OrganicStack Publisher Release Timeline

v1.0.8Current
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

OrganicStack Publisher Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
57 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped57 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
organicstack_publisher_admin (admin-page.php:49)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

OrganicStack Publisher Attack Surface

Entry Points15
Unprotected2

REST API Routes 15

GET/wp-json/organicstack-publisher/v1/pingorganicstack-publisher.php:121
GET/wp-json/organicstack-publisher/v1/test-connectionorganicstack-publisher.php:128
POST/wp-json/organicstack-publisher/v1/authorganicstack-publisher.php:135
POST/wp-json/organicstack-publisher/v1/publishorganicstack-publisher.php:142
POST/wp-json/organicstack-publisher/v1/bulk-publishorganicstack-publisher.php:149
POST/wp-json/organicstack-publisher/v1/upload-mediaorganicstack-publisher.php:156
GET/wp-json/organicstack-publisher/v1/categoriesorganicstack-publisher.php:163
GET/wp-json/organicstack-publisher/v1/tagsorganicstack-publisher.php:170
GET/wp-json/organicstack-publisher/v1/authorsorganicstack-publisher.php:177
GET/wp-json/organicstack-publisher/v1/site-infoorganicstack-publisher.php:184
GET/wp-json/organicstack-publisher/v1/postsorganicstack-publisher.php:191
DELETE/wp-json/organicstack-publisher/v1/posts/(?P<id>\d+)organicstack-publisher.php:198
POST/wp-json/organicstack-publisher/v1/create-authororganicstack-publisher.php:206
GET/wp-json/organicstack-publisher/v1/llms-txtorganicstack-publisher.php:213
POST/wp-json/organicstack-publisher/v1/llms-txtorganicstack-publisher.php:220
WordPress Hooks 7
actionadmin_menuadmin-page.php:9
actionadmin_initadmin-page.php:24
actionrest_api_initorganicstack-publisher.php:64
actioninitorganicstack-publisher.php:65
filterget_avatarorganicstack-publisher.php:69
actiontemplate_redirectorganicstack-publisher.php:72
actiontransition_post_statusorganicstack-publisher.php:74
Maintenance & Trust

OrganicStack Publisher Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 13, 2026
PHP min version7.4
Downloads503

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

OrganicStack Publisher Developer Profile

OrganicStack

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OrganicStack Publisher

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/organicstack-publisher/build/index.js/wp-content/plugins/organicstack-publisher/build/style.css
Script Paths
/wp-content/plugins/organicstack-publisher/build/index.js
Version Parameters
organicstack-publisher/build/index.js?ver=organicstack-publisher/build/style.css?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- AVATAR POLICY - NEVER VIOLATE - CRITICAL FOR MULTI-TENANT --><!-- RULES (DO NOT ADD CODE THAT VIOLATES THESE): --><!-- 1. We ONLY manage organicstack_avatar_id and organicstack_created. Nothing else. --><!-- 2. We NEVER call delete_user_meta() for any avatar-related or author-related meta. -->+7 more
JS Globals
organicstack_publisher_ajax_object
REST Endpoints
/wp-json/organicstack-publisher/v1/ping/wp-json/organicstack-publisher/v1/test-connection/wp-json/organicstack-publisher/v1/auth/wp-json/organicstack-publisher/v1/publish/wp-json/organicstack-publisher/v1/bulk-publish/wp-json/organicstack-publisher/v1/upload-media/wp-json/organicstack-publisher/v1/categories/wp-json/organicstack-publisher/v1/tags/wp-json/organicstack-publisher/v1/authors/wp-json/organicstack-publisher/v1/site-info/wp-json/organicstack-publisher/v1/posts
FAQ

Frequently Asked Questions about OrganicStack Publisher