Pending Indicator Security & Risk Analysis

wordpress.org/plugins/pending-inidicator

Show the number of pending posts waiting for approval in the admin menu, if any. Also automatically supports custom post types.

200 active installs v1.1 PHP + WP 3.5+ Updated Dec 18, 2013
admin-menuindicatorpendingpending-postsposts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pending Indicator Safe to Use in 2026?

Generally Safe

Score 85/100

Pending Indicator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'pending-indicator' plugin version 1.1 exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The lack of file operations, external HTTP requests, and critically, the absence of nonce and capability checks, while unusual for interactive plugins, contribute to a low-risk profile in terms of direct code vulnerabilities. The plugin also has no recorded vulnerability history, further reinforcing its secure reputation.

Vulnerabilities
None known

Pending Indicator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Pending Indicator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Pending Indicator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filteradd_menu_classespending-indicator.php:75
Maintenance & Trust

Pending Indicator Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedDec 18, 2013
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings4
Active installs200
Developer Profile

Pending Indicator Developer Profile

keha

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pending Indicator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
update-pluginsplugin-count
FAQ

Frequently Asked Questions about Pending Indicator