
Post Rotation Security & Risk Analysis
wordpress.org/plugins/post-rotationSet the rotation interval or the allowed time without new posts... and automatically an older post becomes the latest one!
Is Post Rotation Safe to Use in 2026?
Generally Safe
Score 85/100Post Rotation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'post-rotation' plugin v1.9 exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices by utilizing prepared statements for all SQL queries and ensuring all output is properly escaped. The absence of file operations and external HTTP requests further reduces potential attack vectors. Furthermore, the plugin has no recorded vulnerabilities, including no historical CVEs, which indicates a history of stability and security awareness from its developers.
While the static analysis reveals no immediate critical vulnerabilities, the complete absence of nonces and capability checks across all entry points (AJAX, REST API, shortcodes, cron) presents a significant concern. This lack of authorization and validation means that any user, regardless of their role or permissions, could potentially trigger actions within the plugin if an entry point were discovered or exposed. The zero attack surface reported is encouraging, but relying solely on this absence without explicit authorization mechanisms is risky. The plugin's security hinges on the assumption that its entry points are entirely undiscoverable or non-functional, which is a fragile security model.
In conclusion, 'post-rotation' v1.9 has strengths in its handling of SQL and output escaping, and a clean vulnerability history. However, the critical weakness lies in the complete oversight of authentication and authorization for its potential entry points. This could lead to serious security issues if any of these entry points become accessible or if the plugin's functionality is expanded in the future without implementing proper security checks. It's a plugin that appears secure due to a lack of discovered flaws, rather than robust, built-in security measures.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
Post Rotation Security Vulnerabilities
Post Rotation Code Analysis
SQL Query Safety
Output Escaping
Post Rotation Attack Surface
WordPress Hooks 4
Maintenance & Trust
Post Rotation Maintenance & Trust
Maintenance Signals
Community Trust
Post Rotation Alternatives
Saeid Simple Text Rotator
saeid-simple-text-rotator
Saeid Simple Text Rotator uses jQuery Super Simple Text Rotator by Pete R. on a simple shortcode to rotate your texts!
Total Slider
total-slider
Transform your experience with sliders forever. A beautiful, true WYSIWYG interface designed to blend seamlessly with the WordPress core.
Slogan Rotator
slogan-rotator
Show a different slogan every time the visitor refreshes the page.
Translate Multilingual sites – TranslatePress
translatepress-multilingual
Translate your entire site directly from the front-end and go multilingual. Full support for WooCommerce, page builders + Google Translate integration
Ad Inserter – Ad Manager & AdSense Ads
ad-inserter
Manage Google AdSense ads, banners, ad rotation, sticky widgets, AMP ads, ads.txt, tracking, header and footer code, PHP code, global custom fields
Post Rotation Developer Profile
2 plugins · 900 total installs
How We Detect Post Rotation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-rotation/admin/post-rotation-admin.css/wp-content/plugins/post-rotation/admin/post-rotation-admin.js/wp-content/plugins/post-rotation/admin/post-rotation-admin.jspost-rotation/admin/post-rotation-admin.css?ver=post-rotation/admin/post-rotation-admin.js?ver=