RA – New Post Auto Set Status "Private" Security & Risk Analysis

wordpress.org/plugins/ra-new-post-auto-set-status-private

The status of the post exhibited directly from new post is compulsorily changed into "private".

50 active installs v1.0.3 PHP + WP 4.0+ Updated May 14, 2015
defaultpoststatusprivatepublishrains
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is RA – New Post Auto Set Status "Private" Safe to Use in 2026?

Generally Safe

Score 85/100

RA – New Post Auto Set Status "Private" has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "ra-new-post-auto-set-status-private" plugin v1.0.3 exhibits a very strong security posture. The static analysis reveals no identified attack surface entries such as AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code demonstrates excellent security practices by utilizing prepared statements for all SQL queries and ensuring all outputs are properly escaped. The absence of dangerous function calls, file operations, external HTTP requests, nonce checks, and capability checks further reinforces this positive assessment. The taint analysis also found no issues, indicating no unsanitized data flows. The vulnerability history is equally clean, with no known CVEs ever recorded for this plugin.

While the lack of any identified vulnerabilities or attack vectors is a significant strength, it's worth noting that a complete absence of certain security checks, like nonce and capability checks, might be due to the plugin's functionality not requiring them. However, for any future updates or if functionality changes, ensuring these checks are implemented where appropriate will be crucial for maintaining this high security standard. Overall, this plugin appears to be exceptionally well-secured.

Vulnerabilities
None known

RA – New Post Auto Set Status "Private" Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RA – New Post Auto Set Status "Private" Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

RA – New Post Auto Set Status "Private" Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionnew_to_publishra-newpost-status-auto-private.php:40
actiondraft_to_publishra-newpost-status-auto-private.php:41
actionauto-draft_to_publishra-newpost-status-auto-private.php:42
Maintenance & Trust

RA – New Post Auto Set Status "Private" Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedMay 14, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

RA – New Post Auto Set Status "Private" Developer Profile

skuramoto

3 plugins · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RA – New Post Auto Set Status "Private"

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about RA – New Post Auto Set Status "Private"