Pantheon Content Publisher Security & Risk Analysis

wordpress.org/plugins/pantheon-content-publisher

The Pantheon Content Publisher plugin for WordPress enables seamless content publishing from Google Drive and Google Docs directly to WordPress sites.

0 active installs v1.3.5 PHP 8.1.0+ WP 5.7+ Updated Unknown
acfgoogle-docspantheon
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pantheon Content Publisher Safe to Use in 2026?

Generally Safe

Score 100/100

Pantheon Content Publisher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The pantheon-content-publisher plugin, version 1.3.5, exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and output is consistently properly escaped. The plugin also demonstrates good practices with a reasonable number of capability checks and a single nonce check. The absence of any known CVEs in its vulnerability history is a significant positive indicator of its security development and maintenance. However, the analysis does highlight a few areas for potential concern. The presence of file operations and external HTTP requests, while not inherently vulnerable, represent potential attack vectors if not handled with extreme care. The analysis found no taint flows, which is excellent, but this doesn't entirely eliminate the possibility of complex or context-dependent vulnerabilities. The single cron event, while not directly an entry point without further checks, is worth noting as a potential area for future scrutiny if any security concerns arise. Overall, this version appears to be robust, but vigilance regarding external interactions and the handling of file operations is recommended.

Key Concerns

  • File operations present potential risk if not secured
  • External HTTP requests can be a vector if not validated
  • Cron events can be a potential attack vector
Vulnerabilities
None known

Pantheon Content Publisher Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Pantheon Content Publisher Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
0
38 escaped
Nonce Checks
1
Capability Checks
11
File Operations
1
External Requests
5
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared6 total queries

Output Escaping

100% escaped38 total outputs
Attack Surface

Pantheon Content Publisher Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 26
actionadmin_menuapp\Admin.php:28
actionadmin_enqueue_scriptsapp\Admin.php:29
filterintermediate_image_sizes_advancedapp\PccSyncManager.php:275
filterbig_image_size_thresholdapp\PccSyncManager.php:276
filterwp_generate_attachment_metadataapp\PccSyncManager.php:277
actioncpub_generate_thumbnailsapp\Plugin.php:48
actionrest_api_initapp\RestController.php:36
actiontemplate_redirectapp\Settings.php:71
actiontemplate_redirectapp\Settings.php:72
actiontemplate_redirectapp\Settings.php:73
actionpre_get_postsapp\Settings.php:74
actionwp_enqueue_scriptsapp\Settings.php:75
actionadmin_enqueue_scriptsapp\Settings.php:79
actionadmin_menuapp\Settings.php:83
filterpost_row_actionsapp\Settings.php:84
filterpage_row_actionsapp\Settings.php:85
filterwp_list_table_class_nameapp\Settings.php:86
filterthe_contentapp\Settings.php:87
filterwp_kses_allowed_htmlapp\Settings.php:90
filterget_the_excerptapp\Settings.php:91
filterposts_resultsapp\Settings.php:476
filtercomments_openapp\Settings.php:556
filterpings_openapp\Settings.php:557
actionadmin_noticesapp\Settings.php:705
actionplugins_loadedpantheon-content-publisher.php:47
actionplugins_loadedpantheon-content-publisher.php:48

Scheduled Events 1

cpub_generate_thumbnails
Maintenance & Trust

Pantheon Content Publisher Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version8.1.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Pantheon Content Publisher Developer Profile

Pantheon Systems

8 plugins · 39K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pantheon Content Publisher

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pantheon-content-publisher/assets/dist/build/assets/index-a8501542.js/wp-content/plugins/pantheon-content-publisher/assets/dist/build/assets/index-c9e485e9.css/wp-content/plugins/pantheon-content-publisher/src/admin/main.tsx/wp-content/plugins/pantheon-content-publisher/src/scripts/react-refresh-preamble.js/wp-content/plugins/pantheon-content-publisher/assets/dist/build/index.js/wp-content/plugins/pantheon-content-publisher/assets/dist/build/index.css
Script Paths
/wp-content/plugins/pantheon-content-publisher/src/admin/main.tsx/wp-content/plugins/pantheon-content-publisher/src/scripts/react-refresh-preamble.js

HTML / DOM Fingerprints

CSS Classes
content-pub-root
Data Attributes
id="content-pub-root"
JS Globals
window.CPUB_BOOTSTRAP
REST Endpoints
/wp-json/pcc/v1
FAQ

Frequently Asked Questions about Pantheon Content Publisher