publishToMixi Security & Risk Analysis

wordpress.org/plugins/publishtomixi

This plugin allows you to crosspost your entries to mixi.

40 active installs v3.0.2.1 PHP + WP 2.5+ Updated Oct 27, 2010
crosspostmixi
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is publishToMixi Safe to Use in 2026?

Generally Safe

Score 85/100

publishToMixi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The plugin "publishtomixi" v3.0.2.1 exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points indicates a minimal attack surface. The code also demonstrates good practices with 100% of SQL queries using prepared statements and the presence of at least one nonce check. However, a significant concern arises from the low percentage (7%) of properly escaped output, suggesting a high potential for Cross-Site Scripting (XSS) vulnerabilities where dynamic data is displayed to users. The plugin has no recorded vulnerability history, which is a positive indicator, but the lack of taint analysis data makes it impossible to fully assess the risk of sensitive data being mishandled within the plugin's code. Overall, while the plugin avoids common pitfalls like unpatched CVEs and raw SQL, the insufficient output escaping warrants careful consideration.

Key Concerns

  • Low output escaping percentage (7%)
Vulnerabilities
None known

publishToMixi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

publishToMixi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

7% escaped27 total outputs
Attack Surface

publishToMixi Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_initpublishToMixi.php:360
actionadmin_menupublishToMixi.php:361
actiondraft_to_publishpublishToMixi.php:363
actionprivate_to_publishpublishToMixi.php:364
actionpending_to_publishpublishToMixi.php:365
actionfuture_to_publishpublishToMixi.php:366
actionnew_to_publishpublishToMixi.php:367
Maintenance & Trust

publishToMixi Maintenance & Trust

Maintenance Signals

WordPress version tested2.8.1
Last updatedOct 27, 2010
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

publishToMixi Developer Profile

kei51

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect publishToMixi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/publishtomixi/css/p2mixi.css/wp-content/plugins/publishtomixi/js/p2mixi.js
Script Paths
/wp-content/plugins/publishtomixi/js/p2mixi.js
Version Parameters
publishtomixi/css/p2mixi.css?ver=publishtomixi/js/p2mixi.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- publishToMixi Settings -->
Data Attributes
name="p2mixi_username"name="p2mixi_password"name="p2mixi_id"name="p2mixi_header_default"name="p2mixi_footer_default"name="p2mixi_default"+4 more
JS Globals
p2mixi_usernamep2mixi_passwordp2mixi_idp2mixi_defaultp2mixi_header_defaultp2mixi_footer_default+4 more
FAQ

Frequently Asked Questions about publishToMixi