
PubMed Posts Security & Risk Analysis
wordpress.org/plugins/pubmed-postsThis plugin adds a dashboard widget that creates posts from PubMed articles, plus a search widget that finds posts with specific article data.
Is PubMed Posts Safe to Use in 2026?
Generally Safe
Score 85/100PubMed Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pubmed-posts" plugin v1.1.1 exhibits a generally positive security posture with several good practices in place, such as the absence of known vulnerabilities and a limited attack surface. The plugin correctly utilizes prepared statements for all SQL queries and includes nonce and capability checks for its single AJAX handler, indicating an awareness of common security pitfalls. There are no shortcodes, cron events, or REST API routes, further reducing potential entry points for attackers.
However, the static analysis reveals a significant concern regarding output escaping, with only 36% of outputs being properly escaped. This is a substantial weakness that could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. Additionally, the taint analysis identified two flows with unsanitized paths, which, while not flagged as critical or high severity in this specific analysis, warrant attention as they represent potential avenues for injection attacks or other security issues, especially when combined with the output escaping weakness.
The plugin's vulnerability history of zero recorded CVEs is a strong indicator of its past security performance. This, coupled with the lack of dangerous functions and file operations, suggests a well-developed plugin. Nevertheless, the identified output escaping issues and taint flow concerns mean that continued vigilance and code review are recommended, as even seemingly robust plugins can harbor subtle vulnerabilities.
Key Concerns
- Insufficient output escaping (36%)
- Flows with unsanitized paths identified
PubMed Posts Security Vulnerabilities
PubMed Posts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
PubMed Posts Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
PubMed Posts Maintenance & Trust
Maintenance Signals
Community Trust
PubMed Posts Alternatives
Scholar Publications Fetcher
scholar-publications-fetcher
A lightweight and high-performance plugin to fetch, cache, and display your Google Scholar publications in a clean, modern, and responsive card layout …
Kblog Include
kblog-include
Transcludes content from arXiv and other academic repositories.
Kblog Metadata
kblog-metadata
Displays bibliographic metadata both for humans and computers.
Academic Publications Showcase
academic-publications-showcase
Display publications from Zenodo communities or ORCID author profiles with modern card layouts and customizable designs.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
PubMed Posts Developer Profile
3 plugins · 360 total installs
How We Detect PubMed Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pubmed-posts/style.css/wp-content/plugins/pubmed-posts/script.js/wp-content/plugins/pubmed-posts/smoothness/jquery-ui-1.10.3.custom.min.css/wp-content/plugins/pubmed-posts/multiselect/jquery.multiselect.css/wp-content/plugins/pubmed-posts/multiselect/jquery.multiselect.min.js/wp-content/plugins/pubmed-posts/admin.css/wp-content/plugins/pubmed-posts/admin.js/wp-content/plugins/pubmed-posts/textext/css/textext.core.css+7 more/wp-content/plugins/pubmed-posts/script.js/wp-content/plugins/pubmed-posts/admin.js/wp-content/plugins/pubmed-posts/textext/js/textext.core.js/wp-content/plugins/pubmed-posts/textext/js/textext.plugin.tags.js/wp-content/plugins/pubmed-posts/textext/js/textext.plugin.arrow.jspubmed-posts/style.css?ver=pubmed-posts/script.js?ver=pubmed-posts/smoothness/jquery-ui-1.10.3.custom.min.css?ver=pubmed-posts/multiselect/jquery.multiselect.css?ver=pubmed-posts/multiselect/jquery.multiselect.min.js?ver=pubmed-posts/admin.css?ver=pubmed-posts/admin.js?ver=pubmed-posts/textext/css/textext.core.css?ver=pubmed-posts/textext/css/textext.plugin.tags.css?ver=pubmed-posts/textext/css/textext.plugin.arrow.css?ver=pubmed-posts/textext/css/textext.plugin.prompt.css?ver=pubmed-posts/textext/css/textext.plugin.autocomplete.css?ver=pubmed-posts/textext/js/textext.core.js?ver=pubmed-posts/textext/js/textext.plugin.tags.js?ver=pubmed-posts/textext/js/textext.plugin.arrow.js?ver=HTML / DOM Fingerprints
pmp-search-widgetpubMedPosts/wp-json/pubmed-posts/[article_authors][journal_citation][pmid_link][article_abstract]