
POST2PDF Converter Security & Risk Analysis
wordpress.org/plugins/post2pdf-converterThis plugin converts your post/page to PDF for visitors and visitors can download it easily.
Is POST2PDF Converter Safe to Use in 2026?
Generally Safe
Score 85/100POST2PDF Converter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "post2pdf-converter" plugin v0.4.2 exhibits a generally good security posture with no known vulnerabilities and a proactive approach to using prepared statements for SQL queries. The limited attack surface, consisting of a single shortcode, and the presence of nonce and capability checks are positive indicators. However, the static analysis reveals some areas for improvement. The taint analysis indicates two flows with unsanitized paths, which could potentially lead to vulnerabilities if not properly handled within the plugin's logic, despite no critical or high severity issues being identified in the analysis.
Furthermore, the static analysis shows that 74% of output is properly escaped, leaving 26% potentially unescaped. While this might not be critical depending on the nature of the unescaped output, it presents a risk of cross-site scripting (XSS) vulnerabilities. The bundled TCPDF library is also at version 5.9.149, which may be outdated and could contain known or unknown security flaws. Overall, the plugin is relatively secure due to its minimal attack surface and good SQL handling, but the unsanitized paths and potential for unescaped output warrant attention.
Key Concerns
- Flows with unsanitized paths found
- Potentially unescaped output exists
- Bundled library TCPDF v5.9.149 may be outdated
POST2PDF Converter Security Vulnerabilities
POST2PDF Converter Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
POST2PDF Converter Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
POST2PDF Converter Maintenance & Trust
Maintenance Signals
Community Trust
POST2PDF Converter Alternatives
WP Book
wp-book
Download your posts, pages and custom post as a PDF Book in few clicks
Attachments
attachments
Attachments allows you to simply append any number of items from your WordPress Media Library to Posts, Pages, and Custom Post Types
PDF Generator for Posts & Pages – Export Any Post Type to PDF
post-to-pdf
Add a one-click PDF download button to any post, page, or custom post type. Includes a visual layout builder, ACF field support, color control, and sh …
Convert Articles to PDF
convert-articles-to-pdf
Easily convert your WordPress posts into high-quality downloadable PDF documents using DOMPDF.
HTML to PDF Converter
html-to-pdf-converter
A WordPress plugin that allows you to convert any WordPress page or post to a PDF file using the html2pdf.app API.
POST2PDF Converter Developer Profile
7 plugins · 660 total installs
How We Detect POST2PDF Converter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post2pdf-converter/css/pdf_style.css/wp-content/plugins/post2pdf-converter/js/post2pdf-converter.js/wp-content/plugins/post2pdf-converter/js/post2pdf-converter.jspost2pdf-converter/css/pdf_style.css?ver=post2pdf-converter/js/post2pdf-converter.js?ver=HTML / DOM Fingerprints
post2pdf_download_linkdata-post2pdf-iddata-post2pdf-page-titlepost2pdf_conv_params[pdf]