
Post Flow Security & Risk Analysis
wordpress.org/plugins/post-flowThis plugin will schedule 'auto post checks' to publish new posts and/or recycle old posts automatically.
Is Post Flow Safe to Use in 2026?
Generally Safe
Score 100/100Post Flow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'post-flow' plugin v1.0.2 demonstrates a generally strong security posture based on the static analysis. A significant positive is the 100% output escaping and the absence of dangerous functions, file operations, and external HTTP requests. The presence of capability checks on its two REST API routes is also a good practice, preventing unauthorized access to these entry points. Furthermore, the lack of any recorded historical vulnerabilities, critical or otherwise, suggests a history of security-conscious development.
However, there are areas for improvement. The analysis indicates 50% of SQL queries are not using prepared statements, which presents a moderate risk of SQL injection if the inputs to these queries are not rigorously validated. While there are no reported critical taint flows, the potential for SQL injection still exists. Crucially, the absence of nonce checks across all entry points, particularly the REST API routes, is a significant oversight. This leaves these routes potentially vulnerable to Cross-Site Request Forgery (CSRF) attacks.
In conclusion, 'post-flow' v1.0.2 exhibits good security fundamentals, particularly in output handling and the absence of historical vulnerabilities. The primary concerns lie in the use of raw SQL queries and the complete lack of nonce protection for its REST API endpoints, which represent potential attack vectors that should be addressed in future updates.
Key Concerns
- SQL queries not using prepared statements
- No nonce checks on entry points
Post Flow Security Vulnerabilities
Post Flow Code Analysis
SQL Query Safety
Output Escaping
Post Flow Attack Surface
REST API Routes 2
WordPress Hooks 8
Scheduled Events 2
Maintenance & Trust
Post Flow Maintenance & Trust
Maintenance Signals
Community Trust
Post Flow Alternatives
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher
wp-scheduled-posts
Automate your WordPress content scheduling with a visual calendar, auto/manual schedulers, missed‑post handler, social sharing options & templates.
Editorial Calendar
editorial-calendar
0ddcemmihs4a843ekhaoofzosrunf4bl Editorial Calendar allows you to view all your posts, schedule post, make quick edits, and manage your blog by draggi …
Publish to Schedule
publish-to-schedule
Automate your WordPress post scheduling with Publish to Schedule. Set rules for days and times to publish posts automatically, saving you time and ens …
Show Future Posts on Single Post
show-future-posts-on-single-post
Lets you show Future or Schedule Post on Single Posts. It also enables comments for future posts.
Auto Post Expiry Manager
auto-post-expiry-manager
Automatically expire posts and custom post types at a specific date and time. Works with all public post types and uses a lightweight cron scheduler.
Post Flow Developer Profile
3 plugins · 30 total installs
How We Detect Post Flow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-flow/build/index.js/wp-content/plugins/post-flow/build/index.css/wp-content/plugins/post-flow/build/index.jspost-flow/build/index.js?ver=post-flow/build/index.css?ver=HTML / DOM Fingerprints
wrapid="post-flow"postfl_data/wp-json/postfl/v1/settings/wp-json/postfl/v1/log/wp-json/postfl/v1/posts