
Publish View Security & Risk Analysis
wordpress.org/plugins/publish-viewAdds a button so you can save Publish or save Draft and view in one step.
Is Publish View Safe to Use in 2026?
Generally Safe
Score 85/100Publish View has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "publish-view" v2.3.2 plugin exhibits a strong static security posture with no identified entry points into the application that are not protected by authentication. The absence of AJAX handlers, REST API routes, shortcodes, and cron events without proper checks is a significant strength. Furthermore, the code relies entirely on prepared statements for SQL queries, mitigating the risk of SQL injection vulnerabilities. There are also no identified dangerous functions, file operations, or external HTTP requests that could be exploited.
However, a critical concern arises from the output escaping results. With 100% of the identified outputs not being properly escaped, this plugin presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic content rendered by this plugin could be maliciously injected with scripts, compromising user sessions or defacing the website. The lack of documented past vulnerabilities is positive, suggesting the developers may have a good understanding of security, but it does not negate the current risk posed by unescaped output. While the plugin has a small attack surface and uses secure database practices, the lack of output escaping is a severe oversight that needs immediate attention.
Key Concerns
- Outputs not properly escaped
Publish View Security Vulnerabilities
Publish View Code Analysis
Output Escaping
Publish View Attack Surface
WordPress Hooks 7
Maintenance & Trust
Publish View Maintenance & Trust
Maintenance Signals
Community Trust
Publish View Alternatives
Save with keyboard
save-with-keyboard
Save everything in the most natural way by pressing Ctrl+S (or Cmd+S on Mac).
Bulk Post Status Update
bulk-post-status-update
The users can change the status of posts and custom posts to draft and publish them in bulk.
Gtuk unpublish posts
gtuk-unpublish-posts
Adds the possibility to set an upublish date to pages, posts and custom post types.
Quick Save
quick-save
Press the ALT key to update posts and pages instead of clicking the Update button all the time.
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
post-expirator
PublishPress Future can make scheduled changes to your content. You can unpublish posts, move posts to a new status, update the categories, and more.
Publish View Developer Profile
4 plugins · 5K total installs
How We Detect Publish View
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/publish-view/publish-view-dashicons.css/wp-content/plugins/publish-view/publish-view.cssHTML / DOM Fingerprints
pv_wrapname="pv_new_window"name="pv_publish_new_window"id="pv_view_hidden"name="pv_view"id="pv_publish"id="pv_draft"jQuery