
QuickPost – Add New Posts & Duplicate from the Block Editor Security & Risk Analysis
wordpress.org/plugins/quickpostAdds an "Add New" button to the Block Editor (Gutenberg) toolbar, so you can easily create new posts/pages/custom post types without leaving …
Is QuickPost – Add New Posts & Duplicate from the Block Editor Safe to Use in 2026?
Generally Safe
Score 85/100QuickPost – Add New Posts & Duplicate from the Block Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis, the 'quickpost' plugin v0.1.5 exhibits a strong security posture. The plugin demonstrates excellent security practices by having no identified dangerous functions, all SQL queries utilizing prepared statements, and all output being properly escaped. Furthermore, the absence of file operations and external HTTP requests reduces potential attack vectors. The lack of any identified vulnerabilities in its history, including critical or high-severity issues, further reinforces this positive assessment. The plugin's minimal attack surface, with zero entry points identified in AJAX handlers, REST API routes, shortcodes, or cron events, is a significant strength. This suggests the plugin is designed with security in mind from the outset.
However, the static analysis also reveals a complete absence of security checks such as nonce checks and capability checks. While the current attack surface is zero, this absence of standard security controls means that if any entry points were to be introduced in future updates, they would be inherently unprotected. The zero taint flows are also a positive sign, indicating no immediate risks from unsanitized data handling. The vulnerability history being entirely clear suggests a well-maintained or less complex plugin. In conclusion, 'quickpost' v0.1.5 appears to be a secure plugin with robust coding practices and no known vulnerabilities. The primary area for potential improvement lies in the consistent implementation of standard WordPress security mechanisms like nonce and capability checks, even in the absence of current entry points, to ensure future-proofing.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
QuickPost – Add New Posts & Duplicate from the Block Editor Security Vulnerabilities
QuickPost – Add New Posts & Duplicate from the Block Editor Code Analysis
QuickPost – Add New Posts & Duplicate from the Block Editor Attack Surface
WordPress Hooks 1
Maintenance & Trust
QuickPost – Add New Posts & Duplicate from the Block Editor Maintenance & Trust
Maintenance Signals
Community Trust
QuickPost – Add New Posts & Duplicate from the Block Editor Alternatives
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Disable Gutenberg
disable-gutenberg
Disable Gutenberg Block Editor and restore the Classic Editor and original Edit Post screen (TinyMCE, meta boxes, etc.).
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
essential-blocks
Gutenberg block editor with AI. 70+ Gutenberg blocks, patterns, WooCommerce blocks, post grid, gallery, menu with Gutenberg block library.
QuickPost – Add New Posts & Duplicate from the Block Editor Developer Profile
2 plugins · 1K total installs
How We Detect QuickPost – Add New Posts & Duplicate from the Block Editor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quickpost/build/index.js/wp-content/plugins/quickpost/build/index.css/wp-content/plugins/quickpost/build/index.jsquickpost/build/index.css?ver=