Press This v2 Security & Risk Analysis

wordpress.org/plugins/press-this-v2

This is a rewrite of the Press This functionality from core.

10 active installs v0.1 PHP + WP + Updated Jun 28, 2012
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Press This v2 Safe to Use in 2026?

Generally Safe

Score 85/100

Press This v2 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "press-this-v2" plugin v0.1 exhibits a strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with exposed attack vectors significantly reduces the plugin's vulnerability footprint. Furthermore, the code demonstrates good security practices by utilizing prepared statements for all SQL queries and incorporating nonce and capability checks. The low number of identified taint flows, with none exhibiting unsanitized paths or critical/high severity, reinforces this positive assessment. The plugin's vulnerability history being completely clear suggests a history of secure development and maintenance.

While the plugin's current state appears secure, the lack of any recorded vulnerabilities might also indicate a limited history of being a target for attackers or a lack of comprehensive security testing over time. The 74% proper output escaping, while good, still leaves a small margin for potential XSS vulnerabilities if the remaining 26% are used in critical areas, though no such issues were flagged in the taint analysis. Overall, this plugin appears to be well-developed from a security perspective, with a minimal attack surface and good adherence to security best practices.

Key Concerns

  • 74% output escaping, potentially unsafe
Vulnerabilities
None known

Press This v2 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Press This v2 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
54 escaped
Nonce Checks
1
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

74% escaped73 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
press_this_ajax (includes\press-this.php:115)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Press This v2 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_footerincludes\press-this.php:271
filtershortcut_linkpress-this-v2.php:11
actionmedia_buttonspress-this.php:384
Maintenance & Trust

Press This v2 Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedJun 28, 2012
PHP min version
Downloads2K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Alternatives

Press This v2 Alternatives

No alternatives data available yet.

Developer Profile

Press This v2 Developer Profile

George Stephanis

16 plugins · 16K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Press This v2

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/press-this-v2/press-this.php

HTML / DOM Fingerprints

CSS Classes
press-this-wrap
HTML Comments
Press This Display and Handler.WordPress Administration Bootstrap
Data Attributes
id="extra-fields"id="embed-code"id="photo-add-url-div"id="img_container"class="close"class="refresh"
JS Globals
addLoadEventuserSettingsajaxurlpagenowtypenowthousandsSeparator+9 more
FAQ

Frequently Asked Questions about Press This v2