
PDF Generator for Posts & Pages – Export Any Post Type to PDF Security & Risk Analysis
wordpress.org/plugins/post-to-pdfAdd a one-click PDF download button to any post, page, or custom post type. Includes a visual layout builder, ACF field support, color control, and sh …
Is PDF Generator for Posts & Pages – Export Any Post Type to PDF Safe to Use in 2026?
Generally Safe
Score 99/100PDF Generator for Posts & Pages – Export Any Post Type to PDF has a strong security track record. Known vulnerabilities have been patched promptly.
The 'post-to-pdf' plugin version 1.1 exhibits a mixed security posture. While it demonstrates good practices such as exclusively using prepared statements for SQL queries and performing a significant number of nonce and capability checks, there are notable areas of concern. The presence of 7 REST API routes, with one lacking permission callbacks, presents a direct unprotected entry point into the plugin's functionality. This is a significant risk as it could allow unauthorized users to interact with or exploit this endpoint. The plugin also has a history of vulnerabilities, specifically a medium severity Cross-Site Scripting (XSS) issue reported relatively recently. While this specific vulnerability is patched, the recurring nature of such issues suggests potential weaknesses in input sanitization or output escaping that might not be fully captured by static analysis alone.
Key Concerns
- REST API route without permission callback
- Medium severity XSS vulnerability history
- 63% of outputs properly escaped
PDF Generator for Posts & Pages – Export Any Post Type to PDF Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Post to Pdf <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
PDF Generator for Posts & Pages – Export Any Post Type to PDF Code Analysis
SQL Query Safety
Output Escaping
PDF Generator for Posts & Pages – Export Any Post Type to PDF Attack Surface
REST API Routes 7
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
PDF Generator for Posts & Pages – Export Any Post Type to PDF Maintenance & Trust
Maintenance Signals
Community Trust
PDF Generator for Posts & Pages – Export Any Post Type to PDF Alternatives
DK PDF – WordPress PDF Generator
dk-pdf
DK PDF allows your site visitors generate PDF files from WordPress posts, pages, custom post types and WooCommerce products using a button.
PDF Generator for WordPress Elementor
pdf-generator-addon-for-elementor-page-builder
The ultimate WordPress PDF generator for Elementor. Easily export to PDF, add a download button, and convert WooCommerce products to PDF.
WP PDF Generator
wp-pdf-generator
Simply helps you to get your web page download as pdf
WPMK PDF Generator
wpmk-pdf-generator
This Free Plugin will provide you to add download html to pdf
Page2PDF – Posts & Pages to PDF Converter
page2pdf-posts-pages-to-pdf-converter
Transform any WordPress content into professional PDF documents with customizable options. The most powerful print-friendly PDF generator for WordPres …
PDF Generator for Posts & Pages – Export Any Post Type to PDF Developer Profile
26 plugins · 12K total installs
How We Detect PDF Generator for Posts & Pages – Export Any Post Type to PDF
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-to-pdf/build/admin/admin.js/wp-content/plugins/post-to-pdf/build/admin/admin.css/wp-content/plugins/post-to-pdf/build/admin/admin.jspost-to-pdf/build/admin/admin.js?ver=1.0post-to-pdf/build/admin/admin.css?ver=1HTML / DOM Fingerprints
gmptp_button<!-- Output nonce for security --><!-- HTML for the radio buttons --><!-- Retrieve existing value from the database --><!-- Default to 'no' if no value is set -->+10 morename="gmptp_exclude_post_option"value="yes"value="no"name="gmptp_exclude_post_option"id="GMPTP-admin-root"gmwcp_wp_ajax/wp-json/gmptp/v1/moreplugin/wp-json/gmptp/v1/get-settings/wp-json/gmptp/v1/save-settings/wp-json/gmptp/v1/save-customfield/wp-json/gmptp/v1/delete-customfield/wp-json/gmptp/v1/acf-fields[gmptp_single_post]