Publishing Checklist Security & Risk Analysis

wordpress.org/plugins/publishing-checklist

Pre-flight your posts.

200 active installs v0.1.0 PHP + WP 4.2+ Updated Aug 27, 2015
checklisteditorialpreflightpublishing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Publishing Checklist Safe to Use in 2026?

Generally Safe

Score 85/100

Publishing Checklist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin 'publishing-checklist' version 0.1.0 exhibits a strong initial security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the code shows no signs of dangerous functions, raw SQL queries, file operations, or external HTTP requests. While the output escaping is not perfect at 87%, this is a minor concern given the limited attack vectors. The taint analysis also reveals no identified vulnerabilities. The plugin's vulnerability history is completely clean, with no known CVEs, which is a positive indicator. Overall, this plugin appears to be developed with security in mind, prioritizing a minimal attack surface and seemingly safe coding practices. The primary area for improvement, albeit minor, lies in ensuring 100% output escaping for all potential outputs.

Key Concerns

  • Output escaping not 100%
Vulnerabilities
None known

Publishing Checklist Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Publishing Checklist Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

87% escaped15 total outputs
Attack Surface

Publishing Checklist Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionpublishing_checklist_enqueue_scriptspublishing-checklist.php:38
actionpost_submitbox_misc_actionspublishing-checklist.php:39
actionmanage_posts_custom_columnpublishing-checklist.php:40
filtermanage_posts_columnspublishing-checklist.php:41
actioninitpublishing-checklist.php:206
Maintenance & Trust

Publishing Checklist Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedAug 27, 2015
PHP min version
Downloads4K

Community Trust

Rating60/100
Number of ratings2
Active installs200
Developer Profile

Publishing Checklist Developer Profile

Daniel Bachhuber

9 plugins · 51K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Publishing Checklist

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/publishing-checklist/assets/css/publishing-checklist.css/wp-content/plugins/publishing-checklist/assets/js/src/publishing-checklist.js
Script Paths
/wp-content/plugins/publishing-checklist/assets/js/src/publishing-checklist.js
Version Parameters
publishing-checklist.css?ver=publishing-checklist.js?ver=

HTML / DOM Fingerprints

CSS Classes
publishing-checklist-taskspublishing-checklist-task-item
FAQ

Frequently Asked Questions about Publishing Checklist