
Post Status Indicator Security & Risk Analysis
wordpress.org/plugins/post-status-indicatorAllow color customization in WordPress admin for the publish state of your content.
Is Post Status Indicator Safe to Use in 2026?
Generally Safe
Score 85/100Post Status Indicator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The post-status-indicator plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. A significant strength is the complete absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and unsanitized taint flows. The plugin also demonstrates good practice by securing all identified entry points (REST API routes) with permission callbacks and implementing capability checks, indicating a focus on restricting access to sensitive functionalities. Furthermore, the lack of any recorded vulnerabilities, including CVEs, suggests a history of secure development or minimal exposure to common attack vectors.
However, a minor point of concern is the absence of nonce checks on any entry points. While the REST API routes are protected by permission callbacks, nonces are an additional layer of defense against Cross-Site Request Forgery (CSRF) attacks, especially if these routes are intended to be accessible to authenticated users without administrative privileges. The plugin's overall small attack surface (2 entry points) and the fact that these are properly protected mitigate this concern significantly. In conclusion, the plugin is generally secure with a robust foundation, but incorporating nonce checks on its REST API endpoints would further enhance its resilience against CSRF.
Key Concerns
- Missing nonce checks on entry points
Post Status Indicator Security Vulnerabilities
Post Status Indicator Code Analysis
Post Status Indicator Attack Surface
REST API Routes 2
WordPress Hooks 4
Maintenance & Trust
Post Status Indicator Maintenance & Trust
Maintenance Signals
Community Trust
Post Status Indicator Alternatives
LH Archived Post Status
lh-archived-post-status
Allows posts and pages to be archived so you can remove content from the main loop and feed without having to trash it.
LH Inclusive Private Pages
lh-inclusive-private-pages
Extends the CRM possibilities for wordpress by allowing private posts/pages, and other CPt´s to be included in menus and also as the parent of other p …
LH Logged In Post Status
lh-logged-in-post-status
Allows you to restrict access to posts, pges etc to logged in users only.
Post Status Menu Items
post-status-menu-items
Adds post status links–e.g. "Draft" (7)–to post type admin menus and a few other nice goodies.
Pending Status
pending-status
Get notified when your site has posts pending review.
Post Status Indicator Developer Profile
3 plugins · 20K total installs
How We Detect Post Status Indicator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-status-indicator/css/post-status-indicator.css/wp-content/plugins/post-status-indicator/psi-dashboard/dist/js/post-status-indicator.js/wp-content/plugins/post-status-indicator/psi-dashboard/dist/js/post-status-indicator.jspost-status-indicator/css/post-status-indicator.css?ver=post-status-indicator/psi-dashboard/dist/js/post-status-indicator.js?ver=HTML / DOM Fingerprints
status-subsubsubpsi_config/wp-json/psi/v1/settings