Republication Tracker Tool Security & Risk Analysis

wordpress.org/plugins/republication-tracker-tool

Adds a widget to allow readers to easily acquire Creative-Commons-licensed HTML of articles to facilitate embedding posts on external sites.

200 active installs v2.8.0 PHP 7.4+ WP 5.3+ Updated Nov 24, 2025
newspublishers
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Republication Tracker Tool Safe to Use in 2026?

Generally Safe

Score 100/100

Republication Tracker Tool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "republication-tracker-tool" plugin version 2.8.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any registered attack surface points, such as AJAX handlers, REST API routes, shortcodes, or cron events, is a significant positive. Furthermore, the code demonstrates good practices by not utilizing dangerous functions, performing file operations, or making external HTTP requests. The fact that all SQL queries use prepared statements is also commendable and mitigates the risk of SQL injection vulnerabilities.

However, the analysis does reveal some areas for improvement. The taint analysis indicates two flows with unsanitized paths. While these did not escalate to critical or high severity in this instance, they represent potential avenues for exploitation if they were to interact with sensitive data or functionalities. Additionally, the 80% output escaping rate means that 20% of outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs.

The plugin's vulnerability history is clean, with no known CVEs recorded. This suggests a track record of secure development or a lack of past exploitation. In conclusion, while the plugin has a solid foundation with minimal attack surface and good SQL handling, the presence of unsanitized paths and a portion of unescaped output warrant attention to prevent potential future vulnerabilities.

Key Concerns

  • Taint flows with unsanitized paths
  • Unescaped output detected (20%)
Vulnerabilities
None known

Republication Tracker Tool Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Republication Tracker Tool Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
136 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped170 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
widget (includes\class-widget.php:37)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Republication Tracker Tool Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionadd_meta_boxesincludes\class-article-settings.php:41
actionmanage_edit-post_columnsincludes\class-article-settings.php:42
actionmanage_edit-post_sortable_columnsincludes\class-article-settings.php:43
actionmanage_posts_custom_columnincludes\class-article-settings.php:44
actionsave_postincludes\class-article-settings.php:45
actionwp_insert_postincludes\class-article-settings.php:46
actionadd_attachmentincludes\class-media.php:19
actioninitincludes\class-republication-rewrite.php:29
filtertemplate_includeincludes\class-republication-rewrite.php:30
actionwp_enqueue_scriptsincludes\class-republication-rewrite.php:31
actionwp_headincludes\class-republication-rewrite.php:117
actionadmin_initincludes\class-settings.php:32
filterrepublication_tracker_tool_bylineincludes\compatibility-co-authors-plus.php:27
actioninitrepublication-tracker-tool.php:134
actionwidgets_initrepublication-tracker-tool.php:153
filterplugin_row_metarepublication-tracker-tool.php:155
filterquery_varsrepublication-tracker-tool.php:157
filtertemplate_includerepublication-tracker-tool.php:160
actionplugins_loadedrepublication-tracker-tool.php:398
Maintenance & Trust

Republication Tracker Tool Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 24, 2025
PHP min version7.4
Downloads13K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Republication Tracker Tool Developer Profile

Automattic

213 plugins · 19.2M total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
1384 days
View full developer profile
Detection Fingerprints

How We Detect Republication Tracker Tool

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/republication-tracker-tool/includes/licenses.php/wp-content/plugins/republication-tracker-tool/includes/class-settings.php/wp-content/plugins/republication-tracker-tool/includes/class-media.php/wp-content/plugins/republication-tracker-tool/includes/class-content.php/wp-content/plugins/republication-tracker-tool/includes/class-article-settings.php/wp-content/plugins/republication-tracker-tool/includes/class-widget.php/wp-content/plugins/republication-tracker-tool/includes/compatibility-co-authors-plus.php/wp-content/plugins/republication-tracker-tool/includes/class-republication-rewrite.php+1 more
Version Parameters
republication-tracker-tool/republication-tracker-tool.php?ver=

HTML / DOM Fingerprints

Data Attributes
data-parsely-post-id
JS Globals
PARSELY
Shortcode Output
[republication_tracker_attribution]
FAQ

Frequently Asked Questions about Republication Tracker Tool