
Press This v2 Security & Risk Analysis
wordpress.org/plugins/press-this-v2This is a rewrite of the Press This functionality from core.
Is Press This v2 Safe to Use in 2026?
Generally Safe
Score 85/100Press This v2 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "press-this-v2" plugin v0.1 exhibits a strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with exposed attack vectors significantly reduces the plugin's vulnerability footprint. Furthermore, the code demonstrates good security practices by utilizing prepared statements for all SQL queries and incorporating nonce and capability checks. The low number of identified taint flows, with none exhibiting unsanitized paths or critical/high severity, reinforces this positive assessment. The plugin's vulnerability history being completely clear suggests a history of secure development and maintenance.
While the plugin's current state appears secure, the lack of any recorded vulnerabilities might also indicate a limited history of being a target for attackers or a lack of comprehensive security testing over time. The 74% proper output escaping, while good, still leaves a small margin for potential XSS vulnerabilities if the remaining 26% are used in critical areas, though no such issues were flagged in the taint analysis. Overall, this plugin appears to be well-developed from a security perspective, with a minimal attack surface and good adherence to security best practices.
Key Concerns
- 74% output escaping, potentially unsafe
Press This v2 Security Vulnerabilities
Press This v2 Code Analysis
Output Escaping
Data Flow Analysis
Press This v2 Attack Surface
WordPress Hooks 3
Maintenance & Trust
Press This v2 Maintenance & Trust
Maintenance Signals
Community Trust
Press This v2 Alternatives
No alternatives data available yet.
Press This v2 Developer Profile
16 plugins · 16K total installs
How We Detect Press This v2
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/press-this-v2/press-this.phpHTML / DOM Fingerprints
press-this-wrapPress This Display and Handler.WordPress Administration Bootstrapid="extra-fields"id="embed-code"id="photo-add-url-div"id="img_container"class="close"class="refresh"addLoadEventuserSettingsajaxurlpagenowtypenowthousandsSeparator+9 more