
ReactPress – Create React App for WordPress Security & Risk Analysis
wordpress.org/plugins/reactpressEasily create, build and deploy React apps into your existing WordPress sites.
Is ReactPress – Create React App for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100ReactPress – Create React App for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ReactPress v3.4.0 plugin exhibits a concerning security posture primarily due to its significant unprotected attack surface. While the plugin demonstrates good practices in its SQL query handling, utilizing prepared statements exclusively, and has no recorded historical vulnerabilities, these strengths are overshadowed by critical weaknesses identified in the static analysis.
The most significant risk lies in the presence of one AJAX handler that lacks any authentication checks. This directly exposes an entry point to potential attackers, allowing them to interact with the plugin's functionality without proper authorization. Furthermore, the absence of nonce checks and capability checks on this entry point exacerbates the risk, making it susceptible to CSRF attacks and unauthorized privilege escalation if the AJAX handler performs sensitive operations.
While the plugin has a clean vulnerability history, which is positive, it doesn't mitigate the immediate risks presented by the current code. The lack of proper output escaping on a significant portion of its outputs (58%) also presents a risk of XSS vulnerabilities. In conclusion, despite good SQL practices and a clean history, the unprotected AJAX handler, lack of nonces/capabilities, and insufficient output escaping make this plugin a considerable security risk.
Key Concerns
- Unprotected AJAX handler
- Missing nonce checks
- Missing capability checks
- Insufficient output escaping
ReactPress – Create React App for WordPress Security Vulnerabilities
ReactPress – Create React App for WordPress Code Analysis
SQL Query Safety
Output Escaping
ReactPress – Create React App for WordPress Attack Surface
AJAX Handlers 1
WordPress Hooks 14
Maintenance & Trust
ReactPress – Create React App for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
ReactPress – Create React App for WordPress Alternatives
GoEmbed – Javascript Application Embedded
go-embed
The idea to embed a Modern Javascript Application into WordPress page
Include Custom Files
include-custom-files
Enables embedding of multiple stylesheets and javascript files on a per-post basis.
SOGO Add Script to Individual Pages Header Footer
oh-add-script-header-footer
Simple plugin to add script to header and footer for individual pages & posts
PDF.js Viewer
pdfjs-viewer-shortcode
Embed a beautiful PDF viewer into pages.
PDF viewer for Elementor & Gutenberg
pdfjs-viewer-for-elementor
The "PDFjs Viewer for Elementor & Gutenberg" plugin is a powerful tool that allows you to embed PDF files into your Elementor page build …
ReactPress – Create React App for WordPress Developer Profile
2 plugins · 3K total installs
How We Detect ReactPress – Create React App for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reactpress/admin/css/reactpress-admin.css/wp-content/plugins/reactpress/admin/js/reactpress-admin.js/wp-content/plugins/reactpress/admin/js/reactpress-admin.jsreactpress-admin.css?ver=reactpress-admin.js?ver=HTML / DOM Fingerprints
reactpress-admin-wrapdata-reactpress-apprp/wp-json/reactpress/v1