
Posts To-Do List Security & Risk Analysis
wordpress.org/plugins/posts-to-do-listShare post ideas with writers, suggest them writing topics and keep track of the posts ideas with a to-do list.
Is Posts To-Do List Safe to Use in 2026?
Generally Safe
Score 100/100Posts To-Do List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "posts-to-do-list" plugin version 1.4.4 presents a significant security risk due to a large, unprotected attack surface. All 11 identified AJAX entry points lack authentication checks, making them prime targets for unauthorized actions. The presence of the `unserialize` function, while not explicitly shown to be exploited in taint analysis, is a known dangerous function that can lead to remote code execution if used with untrusted input. Furthermore, only 25% of output is properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities. The absence of any recorded vulnerabilities in its history is positive, but this could be due to a lack of sophisticated testing or obscurity, rather than inherent security. The plugin demonstrates a concerning disregard for basic WordPress security practices, particularly concerning AJAX endpoints and output sanitization. While it does utilize prepared statements for a majority of its SQL queries, this is overshadowed by the critical lack of authorization on its primary interaction points.
Key Concerns
- 11 unprotected AJAX handlers
- Dangerous function: unserialize
- Only 25% of outputs properly escaped
- Only 1 capability check on 11 entry points
Posts To-Do List Security Vulnerabilities
Posts To-Do List Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Posts To-Do List Attack Surface
AJAX Handlers 11
WordPress Hooks 12
Maintenance & Trust
Posts To-Do List Maintenance & Trust
Maintenance Signals
Community Trust
Posts To-Do List Alternatives
Delete Posts By URL
delete-posts-by-url
Advanced bulk deletion of WordPress posts with multiple filtering options and powerful features for content management.
Auto-Schedule Posts
auto-schedule-posts
Auto-Schedule Posts allows users to separate their writing schedule from their publishing schedule - write when you want and have posts publish at the …
Auto Post Publisher
auto-post-publisher
Automatically publishes scheduled posts that may have missed their scheduled time.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Posts To-Do List Developer Profile
6 plugins · 3K total installs
How We Detect Posts To-Do List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/posts-to-do-list/style/images/ajax-loader.gifposts-to-do-list/style/images/ajax-loader.gif?ver=HTML / DOM Fingerprints
ptdl_widget_titledata-widget-id