
Pterotype Security & Risk Analysis
wordpress.org/plugins/pterotypePterotype expands your audience by giving your blog an ActivityPub stream, making it a part of the Fediverse.
Is Pterotype Safe to Use in 2026?
Generally Safe
Score 85/100Pterotype has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pterotype" plugin v1.4.3 exhibits significant security concerns primarily due to its extensive, unprotected attack surface and lack of output escaping. While the plugin does not appear to have a history of known vulnerabilities and utilizes prepared statements for a majority of its SQL queries, the 10 unprotected REST API routes present a substantial risk. Any sensitive functionality exposed through these endpoints could be leveraged by unauthenticated users, leading to potential data leakage or unauthorized actions. The absence of any output escaping is particularly alarming, as it opens the door to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into user interfaces. The presence of a flow with an unsanitized path in taint analysis, though not critical or high severity, warrants further investigation as it suggests a potential avenue for file system manipulation or other unintended behaviors. Overall, the plugin has a poor security posture due to the direct exposure of numerous entry points without proper authorization or sanitization, despite its lack of historical CVEs.
Key Concerns
- 10 unprotected REST API routes
- 0% properly escaped output
- Flow with unsanitized paths
- No nonce checks
- No capability checks
Pterotype Security Vulnerabilities
Pterotype Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Pterotype Attack Surface
REST API Routes 10
WordPress Hooks 23
Maintenance & Trust
Pterotype Maintenance & Trust
Maintenance Signals
Community Trust
Pterotype Alternatives
ActivityPub
activitypub
Connect your site to the Open Social Web and let millions of users follow, share, and interact with your content from Mastodon, Pixelfed, and more.
NodeInfo(2)
nodeinfo
NodeInfo and NodeInfo2 for WordPress!
Enable Mastodon Apps
enable-mastodon-apps
Allow accessing your WordPress with Mastodon clients. Just enter your own blog URL as your instance.
Event Bridge for ActivityPub
event-bridge-for-activitypub
Integrating popular event plugins with the ActivityPub plugin.
FediBoost
fediboost
Automatically boost WordPress posts on connected Mastodon accounts when published via ActivityPub.
Pterotype Developer Profile
1 plugin · 10 total installs
How We Detect Pterotype
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pterotype/js/icon-upload.jsHTML / DOM Fingerprints
image-preview-wrapperid="pterotype_blog_icon_image"id="pterotype_blog_icon"id="pterotype_blog_icon_button"/wp-json/pterotype/v1/actor//wp-json/pterotype/v1/outbox//wp-json/pterotype/v1/inbox//wp-json/pterotype/v1/object//wp-json/pterotype/v1/following//wp-json/pterotype/v1/followers//wp-json/pterotype/v1/likes//wp-json/pterotype/v1/shares/