Post Webhook – Send Post & Page data to any API or external service Security & Risk Analysis

wordpress.org/plugins/post-webhook

Automate your content workflow by automatically sending post and page data to external services.

70 active installs v1.0.0 PHP 7.0+ WP 4.7+ Updated Oct 22, 2022
apiautomationintegromatwebhookszapier
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Webhook – Send Post & Page data to any API or external service Safe to Use in 2026?

Generally Safe

Score 85/100

Post Webhook – Send Post & Page data to any API or external service has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The post-webhook v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and ensuring all output is properly escaped. The absence of file operations and the handling of external HTTP requests also suggest a controlled environment.

However, the analysis also highlights potential areas for concern. The plugin has no observed AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. While this might seem positive, it could also indicate limited functionality or a lack of mechanisms to integrate with WordPress core, which could be a limitation rather than a security feature. Furthermore, the complete absence of nonce checks, coupled with only one capability check and zero AJAX handlers without authentication, raises questions about how user interactions are secured if any were to be introduced. The zero taint analysis results are positive, but this could be a reflection of the limited attack surface rather than inherently secure taint handling.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the strong static analysis findings, suggests a well-developed and secure plugin. The plugin's strengths lie in its robust handling of data and its lack of known vulnerabilities. The primary weakness, if one can be inferred, is the potential lack of robust input validation and authorization mechanisms for any future additions to its attack surface due to the complete absence of nonce checks.

Key Concerns

  • No nonce checks found
  • Limited capability checks (1 total)
Vulnerabilities
None known

Post Webhook – Send Post & Page data to any API or external service Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Post Webhook – Send Post & Page data to any API or external service Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 16, 2026

Post Webhook – Send Post & Page data to any API or external service Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface

Post Webhook – Send Post & Page data to any API or external service Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuadmin\settings.php:14
actionadmin_initadmin\settings.php:15
filterplugin_action_links_post-webhook-wp/post-webhook-wp.phpadmin\settings.php:33
actionwp_after_insert_postpost-webhook-wp.php:36
actionpublish_to_trashpost-webhook-wp.php:37
Maintenance & Trust

Post Webhook – Send Post & Page data to any API or external service Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 22, 2022
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Post Webhook – Send Post & Page data to any API or external service Developer Profile

JonWright

1 plugin · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Webhook – Send Post & Page data to any API or external service

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Post Webhook – Send Post & Page data to any API or external service