
Public Post Preview Configurator Security & Risk Analysis
wordpress.org/plugins/public-post-preview-configuratorEnables you to configure the 'public post preview' plugin with a user interface.
Is Public Post Preview Configurator Safe to Use in 2026?
Generally Safe
Score 85/100Public Post Preview Configurator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "public-post-preview-configurator" plugin v1.0.3 exhibits a generally strong security posture with no recorded vulnerabilities or critical security signals in the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, cron events, file operations, and external HTTP requests significantly limits its attack surface, which is a positive indicator. The code also demonstrates good output escaping practices, with 86% of outputs properly escaped, and a complete lack of dangerous functions or taint flows.
However, there are a couple of areas that warrant attention. The presence of a single SQL query that does not use prepared statements is a potential risk. While the attack surface is minimal, any SQL injection vulnerability, however unlikely given the other factors, could still have significant consequences. Furthermore, the complete absence of nonce checks and capability checks across all entry points (even though there are none currently) is a missed opportunity for robust security hardening that could be problematic if new entry points are added in the future without these checks.
Overall, the plugin appears to be developed with security in mind, and the lack of historical vulnerabilities further reinforces this. The primary concern is the single unescaped SQL query. The lack of explicit nonce and capability checks is more of a preventative measure that would be beneficial but doesn't represent an immediate, evident risk given the current state of the plugin's attack surface. It's a good foundation, but small improvements can enhance its resilience.
Key Concerns
- SQL query without prepared statements
- No nonce checks on entry points
- No capability checks on entry points
Public Post Preview Configurator Security Vulnerabilities
Public Post Preview Configurator Code Analysis
SQL Query Safety
Output Escaping
Public Post Preview Configurator Attack Surface
WordPress Hooks 6
Maintenance & Trust
Public Post Preview Configurator Maintenance & Trust
Maintenance Signals
Community Trust
Public Post Preview Configurator Alternatives
Public Post Preview
public-post-preview
Allow anonymous users to preview a draft of a post before it is published.
Non Cache Public Post Preview
non-cache-ppp
Disable cache when show public post preview post
Post Draft Preview
post-draft-preview
Allow non logged-in users to check a draft of unpublished post by using secret link
Simple Preview
simple-preview
Let anonymous users preview a post before it is published!
TDD Recent Posts
tdd-recent-posts
Simple widget that displays the recent posts with a short content preview. Control the length of the content preview and number of posts
Public Post Preview Configurator Developer Profile
4 plugins · 10K total installs
How We Detect Public Post Preview Configurator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/public-post-preview-configurator/public-post-preview-configurator/public-post-preview-configurator.php?ver=public-post-preview-configurator/public/js/public-post-preview-configurator.js?ver=public-post-preview-configurator/admin/css/public-post-preview-configurator-admin.css?ver=