
Published By Security & Risk Analysis
wordpress.org/plugins/published-byTrack which user actually published a post, separate from who created the post. Display that info as a column in admin post listings.
Is Published By Safe to Use in 2026?
Generally Safe
Score 85/100Published By has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "published-by" plugin v1.3 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, external HTTP requests, and crucially, the lack of a significant attack surface (AJAX handlers, REST API routes, shortcodes, cron events) that is exposed without authentication or capability checks, are all positive indicators. The plugin also appears to be free from any recorded vulnerabilities, past or present, which suggests a history of secure development. However, the analysis does highlight a potential area for improvement regarding output escaping, with 17% of outputs not being properly escaped. While this may not currently represent a critical risk, it could become a vector for Cross-Site Scripting (XSS) vulnerabilities if malicious data is ever processed and displayed without adequate sanitization. The complete absence of taint analysis flows also means that the effectiveness of sanitization and the potential for more subtle vulnerabilities remain unconfirmed. Therefore, while the plugin is currently in a good security state, vigilance regarding output sanitization is recommended to maintain this high standard.
Key Concerns
- Unescaped output detected
Published By Security Vulnerabilities
Published By Release Timeline
Published By Code Analysis
SQL Query Safety
Output Escaping
Published By Attack Surface
WordPress Hooks 13
Maintenance & Trust
Published By Maintenance & Trust
Maintenance Signals
Community Trust
Published By Alternatives
Darven – Who Published
darven-who-published
Preserves and displays the original user who published a post, even after edits or updates.
Pre-Publish Checklist
pre-publish-checklist
Easiest way to make sure your page or post is ready to go live
Publish Post Email Notification
publish-post-email-notification
Publish post notification is plugin which will send an automatic email to its author when the post is published and approved by WP admin.
Author Website Templates – Create Writer, Author & Publisher Websites Easily
author-website-templates
Effortlessly design stunning websites for authors, writers, publishers, and bloggers with Elementor using Author Website Templates.
Git it Write – Write posts from GitHub
git-it-write
Publish markdown files present in a GitHub repository as posts to WordPress automatically
Published By Developer Profile
63 plugins · 92K total installs
How We Detect Published By
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
published-by/style.css?ver=published-by/script.js?ver=HTML / DOM Fingerprints
c2c-published-byc2c-published-by-guessdata-c2c-published-by-post-idc2c_published_by_settings/wp-json/published-by/v1/settings