
Post by Weekday Security & Risk Analysis
wordpress.org/plugins/post-by-weekdayPosting by day of the week is an easy way to manage posts
Is Post by Weekday Safe to Use in 2026?
Generally Safe
Score 85/100Post by Weekday has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post-by-weekday" plugin version 2.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests. The absence of known vulnerabilities in its history is also a positive indicator. However, significant concerns arise from the static analysis. The plugin has one AJAX handler, and critically, this handler lacks any authentication checks, creating a direct entry point for attackers. While taint analysis shows no critical or high severity unsanitized paths, the presence of two flows with unsanitized paths, albeit not reaching critical levels, warrants attention, especially in conjunction with the unprotected AJAX handler. The lack of nonce checks and capability checks on the AJAX handler further exacerbates the risk, as it allows any user to potentially trigger actions without proper verification. The plugin's vulnerability history is clean, suggesting a generally well-maintained codebase in the past, but this cannot compensate for the immediate security flaws identified in the current version's analysis. Overall, while the plugin avoids some common pitfalls, the unprotected AJAX endpoint presents a clear and present danger that requires immediate remediation.
Key Concerns
- AJAX handler without authentication check
- AJAX handler without nonce check
- AJAX handler without capability check
- Flows with unsanitized paths
Post by Weekday Security Vulnerabilities
Post by Weekday Release Timeline
Post by Weekday Code Analysis
Output Escaping
Data Flow Analysis
Post by Weekday Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Post by Weekday Maintenance & Trust
Maintenance Signals
Community Trust
Post by Weekday Alternatives
Yoast Duplicate Post
duplicate-post
The go-to tool for cloning posts and pages, including the powerful Rewrite & Republish feature.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Regenerate Thumbnails
regenerate-thumbnails
Regenerate the thumbnails for one or more of your image uploads. Useful when changing their sizes or your theme.
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Post by Weekday Developer Profile
1 plugin · 0 total installs
How We Detect Post by Weekday
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-by-weekday/script.min.jsscript.min.jsHTML / DOM Fingerprints
fpost_media_linkwin-weekday-ui-wrapwin-weekday-ui-containerlistdayid="tb_window"id="add_weekday"id="win-weekday-ui-container"id="listday"name="weekday[]"id="btn-pbwd"+1 more<a href="#TB_inline?&inlineId=tb_window" class=" button fpost_media_link thickbox" id="add_weekday" title="Choose Weekday"><span class="dashicons dashicons-calendar-alt"></span><span>Choose Weekday</span><div id="tb_window" style="display: none;">