
PublishPress Statuses – Custom Post Status and Workflow Security & Risk Analysis
wordpress.org/plugins/publishpress-statusesThe PublishPress Statuses plugin allows you to create additional statuses for your posts. You can use each status to create publishing workflows.
Is PublishPress Statuses – Custom Post Status and Workflow Safe to Use in 2026?
Generally Safe
Score 100/100PublishPress Statuses – Custom Post Status and Workflow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The PublishPress Statuses plugin v1.2.4 exhibits a generally positive security posture, with a strong emphasis on output escaping and a significant number of capability checks. The absence of known CVEs and taint analysis findings indicates good development practices regarding common vulnerability types. However, the presence of two unprotected AJAX handlers represents a notable concern. These entry points, without proper authentication or authorization checks, could be exploited by attackers to perform unintended actions or access sensitive data. While the majority of SQL queries use prepared statements, and there are no indications of dangerous functions or file operations, these unprotected AJAX endpoints remain a significant weakness in an otherwise well-secured plugin.
Key Concerns
- 2 unprotected AJAX handlers
PublishPress Statuses – Custom Post Status and Workflow Security Vulnerabilities
PublishPress Statuses – Custom Post Status and Workflow Release Timeline
PublishPress Statuses – Custom Post Status and Workflow Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
PublishPress Statuses – Custom Post Status and Workflow Attack Surface
AJAX Handlers 4
WordPress Hooks 105
Maintenance & Trust
PublishPress Statuses – Custom Post Status and Workflow Maintenance & Trust
Maintenance Signals
Community Trust
PublishPress Statuses – Custom Post Status and Workflow Alternatives
Pending Status
pending-status
Get notified when your site has posts pending review.
Mailchimp for WooCommerce
mailchimp-for-woocommerce
Connect your store to your Mailchimp audience to track sales, create targeted emails, send abandoned cart emails, and more.
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
post-expirator
PublishPress Future can make scheduled changes to your content. You can unpublish posts, move posts to a new status, update the categories, and more.
Zapier for WordPress
zapier
Zapier saves you time on tedious tasks by moving info between WordPress and your other favorite apps, so you can focus on your most important work.
Edit Flow
edit-flow
Redefining your editorial workflow.
PublishPress Statuses – Custom Post Status and Workflow Developer Profile
11 plugins · 272K total installs
How We Detect PublishPress Statuses – Custom Post Status and Workflow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/publishpress-statuses/assets/css/statuses.css/wp-content/plugins/publishpress-statuses/assets/js/statuses.js/wp-content/plugins/publishpress-statuses/assets/js/admin-script.js/wp-content/plugins/publishpress-statuses/assets/js/statuses.js/wp-content/plugins/publishpress-statuses/assets/js/admin-script.jspublishpress-statuses/assets/css/statuses.css?ver=publishpress-statuses/assets/js/statuses.js?ver=publishpress-statuses/assets/js/admin-script.js?ver=HTML / DOM Fingerprints
publishpress-statuses-admindata-statuses-plugin-settingsPublishPressStatuses/wp-json/publishpress-statuses/v1/statuses