
Public Post Preview Security & Risk Analysis
wordpress.org/plugins/public-post-previewAllow anonymous users to preview a draft of a post before it is published.
Is Public Post Preview Safe to Use in 2026?
Generally Safe
Score 100/100Public Post Preview has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "public-post-preview" plugin version 3.1.0 demonstrates a strong security posture based on the provided static analysis. The code exhibits excellent practices, with all identified AJAX handlers and REST API routes (though none were present in this analysis) being protected by proper authentication and capability checks. Furthermore, the plugin adheres to secure coding standards by using prepared statements for all SQL queries and properly escaping all output, indicating a low risk of common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. The lack of any recorded vulnerabilities in its history also suggests a history of secure development and maintenance.
While the static analysis reveals no immediate security concerns, the limited attack surface (one AJAX handler) means that the absence of vulnerabilities might be partly due to the plugin's limited functionality and thus limited exposure. The plugin also includes two nonce checks, which is a positive indicator of security awareness. However, the absence of taint analysis data limits a deeper understanding of potential data flow vulnerabilities. Overall, based on the provided data, this plugin appears to be secure and well-developed, with no significant risks identified.
Public Post Preview Security Vulnerabilities
Public Post Preview Code Analysis
Output Escaping
Public Post Preview Attack Surface
AJAX Handlers 1
WordPress Hooks 18
Maintenance & Trust
Public Post Preview Maintenance & Trust
Maintenance Signals
Community Trust
Public Post Preview Alternatives
Public Post Preview Configurator
public-post-preview-configurator
Enables you to configure the 'public post preview' plugin with a user interface.
Simple Preview
simple-preview
Let anonymous users preview a post before it is published!
Non Cache Public Post Preview
non-cache-ppp
Disable cache when show public post preview post
Share a Draft
shareadraft
Share private preview links to your drafts
Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress
easy-post-submission
Enable users to submit posts and manage profiles from the front-end. Ideal for news, magazines, and creative platforms.
Public Post Preview Developer Profile
6 plugins · 106K total installs
How We Detect Public Post Preview
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/public-post-preview/js/dist/gutenberg-integration.js/wp-content/plugins/public-post-preview/js/public-post-preview.js/wp-content/plugins/public-post-preview/js/public-post-preview.min.jsjs/dist/gutenberg-integration.asset.phppublic-post-preview/js/public-post-preview.js?ver=public-post-preview/js/public-post-preview.min.js?ver=HTML / DOM Fingerprints
dashicons-format-linksdata-post-idDSPublicPostPreviewDataDSPublicPostPreviewL10n/wp-json/public-post-preview/v1/preview