
Post Status Scheduler Security & Risk Analysis
wordpress.org/plugins/post-status-schedulerChange status, categories/tags or postmeta of any post type at a scheduled timestamp.
Is Post Status Scheduler Safe to Use in 2026?
Generally Safe
Score 85/100Post Status Scheduler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The post-status-scheduler plugin v1.3.1 exhibits a mixed security posture. While it boasts a small attack surface with no identified unauthenticated entry points and no known past vulnerabilities, several code signals raise concerns. The presence of the `unserialize` function is a significant risk, as it can lead to Remote Code Execution (RCE) if data passed to it is not rigorously sanitized. Furthermore, the plugin uses SQL queries without prepared statements, which makes it susceptible to SQL injection attacks. The low percentage of properly escaped output also increases the risk of Cross-Site Scripting (XSS) vulnerabilities.
Despite the absence of documented vulnerabilities, the potential for RCE via unserialization and SQL injection remains. The lack of nonce checks on its single shortcode (the only entry point analyzed) is also a weakness, though it's unclear if this entry point is intended to handle user-supplied data in a way that would be exploitable. The vulnerability history being clean is positive, suggesting developers may be responsive to security, but the current code analysis reveals latent risks that need addressing. Overall, the plugin has potential, but critical security flaws in data handling and database interaction need immediate attention.
Key Concerns
- Use of unserialize without clear sanitization
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- No nonce checks on entry points
Post Status Scheduler Security Vulnerabilities
Post Status Scheduler Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Post Status Scheduler Attack Surface
Shortcodes 1
WordPress Hooks 10
Scheduled Events 1
Maintenance & Trust
Post Status Scheduler Maintenance & Trust
Maintenance Signals
Community Trust
Post Status Scheduler Alternatives
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
SEO Auto Linker
wpa-seo-auto-linker
SEO Auto Linker assists in creating cornerstone SEO content. This is not a full replacement for SEO plugins.
SEO Links Generator
seo-links-generator
With SEO Links Generator you can easily add links (automatically) for keywords and phrases in posts, pages and comments.
Post Tags and Categories for Pages
post-tags-and-categories-for-pages
Adds the built in WordPress categories and tags to your pages.
Flexible Posts Widget
flexible-posts-widget
An advanced posts display widget with many options. Display posts in your sidebars any way you'd like!
Post Status Scheduler Developer Profile
2 plugins · 40 total installs
How We Detect Post Status Scheduler
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-status-scheduler/assets/css/backend.css/wp-content/plugins/post-status-scheduler/assets/js/backend.js/wp-content/plugins/post-status-scheduler/assets/js/backend.jspost-status-scheduler/assets/css/backend.css?ver=post-status-scheduler/assets/js/backend.js?ver=HTML / DOM Fingerprints
pss-post-status-scheduler-optionspss-post-status-scheduler-fielddata-pss-datedata-pss-timedata-pss-statusdata-pss-category-actiondata-pss-meta-keypost_status_scheduler_params