
ReVivify Social Security & Risk Analysis
wordpress.org/plugins/revivify-socialPlugin that facilitates auto post sharing and scheduling on social networks, keeping the content alive and active.
Is ReVivify Social Safe to Use in 2026?
Generally Safe
Score 100/100ReVivify Social has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The revivify-social plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and has a history of zero recorded vulnerabilities. The taint analysis also shows no identified flows with unsanitized paths, indicating careful handling of data that could lead to injection attacks. However, the static analysis reveals several areas of concern that temper this positive outlook.
The primary weaknesses lie in its entry points and authorization mechanisms. With a total of 7 entry points, one REST API route is identified as unprotected, meaning it lacks proper permission callbacks. This unprotected endpoint represents a significant risk, as it could be accessed by unauthenticated users, potentially leading to unauthorized actions or information disclosure depending on its functionality. Furthermore, only 3 out of 6 AJAX handlers have nonce checks, leaving the remaining 3 vulnerable to CSRF attacks. The plugin also has a notable number of file operations (7) and external HTTP requests (4) without clear indications of how these are secured or validated.
While the plugin's vulnerability history is currently clean, this does not guarantee future security. The presence of unprotected entry points and insufficient nonce checks on AJAX handlers are known attack vectors. The lack of capability checks across the board, coupled with a significant percentage of improperly escaped outputs (25%), further elevates the risk. Although no critical or high severity taint flows were found, the general lack of robust access control and output sanitization on certain components creates potential opportunities for attackers. In conclusion, while the plugin has strengths in its SQL handling and zero-known CVEs, the identified unprotected REST API route and missing nonce checks on AJAX handlers are critical security weaknesses that require immediate attention.
Key Concerns
- Unprotected REST API route
- 3 AJAX handlers without nonce checks
- 25% of outputs not properly escaped
- Zero capability checks across entry points
ReVivify Social Security Vulnerabilities
ReVivify Social Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
ReVivify Social Attack Surface
AJAX Handlers 6
REST API Routes 1
WordPress Hooks 8
Scheduled Events 1
Maintenance & Trust
ReVivify Social Maintenance & Trust
Maintenance Signals
Community Trust
ReVivify Social Alternatives
Social Web Suite – Social Media Auto Post, Social Media Auto Publish
social-web-suite
Social media auto post, social media auto publish, schedule, share, and promote your new, and re-share your old posts to Instagram, X(Twitter), Facebo …
Post to Social Media – WordPress to Hootsuite
wp-to-hootsuite
Automatically share WordPress Pages, Posts or Custom Post Types to Facebook, Twitter and LinkedIn using your Hootsuite (hootsuite.com) account.
Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media
evergreen-content-poster
Automatically share your best WordPress content (posts/pages/custom post types) to X (Twitter), Mastodon, Facebook, Instagram, Pinterest, LinkedIn and …
Auto Post to Social Media from Social Champ
auto-post-to-social-media-wp-to-social-champ
It sends WP Pages, Posts or Custom Post Types to your Social Champ (SocialChamp.com) account for immediate or scheduled publishing to social networks.
PR-Gateway Connect
pr-gateway-connect
Dear user,
ReVivify Social Developer Profile
1 plugin · 0 total installs
How We Detect ReVivify Social
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/revivify-social/admin/css/main.css/wp-content/plugins/revivify-social/admin/css/bootstrap.css/wp-content/plugins/revivify-social/admin/js/revivify_social_admin.js/wp-content/plugins/revivify-social/admin/js/bootstrap.js/wp-content/plugins/revivify-social/admin/js/tinymce/tinymce.min.js/wp-content/plugins/revivify-social/admin/js/tinymce/plugins/paste/plugin.min.js/wp-content/plugins/revivify-social/admin/js/tinymce/plugins/fullscreen/plugin.min.js/wp-content/plugins/revivify-social/admin/js/tinymce/plugins/textcolor/plugin.min.js+4 morerevivify-social/admin/css/main.css?ver=revivify-social/admin/css/bootstrap.css?ver=revivify-social/admin/js/revivify_social_admin.js?ver=revivify-social/admin/js/bootstrap.js?ver=revivify-social/admin/js/tinymce/tinymce.min.js?ver=revivify-social/admin/js/tinymce/plugins/paste/plugin.min.js?ver=revivify-social/admin/js/tinymce/plugins/fullscreen/plugin.min.js?ver=revivify-social/admin/js/tinymce/plugins/textcolor/plugin.min.js?ver=revivify-social/admin/js/tinymce/plugins/wordpress/plugin.min.js?ver=revivify-social/admin/js/tinymce/themes/silver/theme.min.js?ver=revivify-social/admin/js/social-login/fb-login.js?ver=revivify-social/admin/js/social-login/tw-login.js?ver=HTML / DOM Fingerprints
revivify-social-settingsROdata-tinymce-optionstinyMCErevivify_social_ajax_object/twitter/callback