
Seraphinite Post .DOCX Source Security & Risk Analysis
wordpress.org/plugins/seraphinite-post-docx-sourceSave your time by automatically converting from .DOCX to content with all WordPress post attributes.
Is Seraphinite Post .DOCX Source Safe to Use in 2026?
Generally Safe
Score 98/100Seraphinite Post .DOCX Source has a strong security track record. Known vulnerabilities have been patched promptly.
The seraphinite-post-docx-source plugin exhibits a mixed security posture. While it has no currently unpatched CVEs, its static analysis reveals significant concerns. The presence of two AJAX handlers without authentication checks represents a substantial attack surface, leaving the plugin vulnerable to unauthorized actions. Furthermore, the use of dangerous functions like 'unserialize' and 'proc_open' combined with a low percentage of properly escaped output (27%) indicates a risk of code injection and sensitive data exposure. Taint analysis, while not revealing critical or high severity issues, did identify two flows with unsanitized paths, suggesting potential for vulnerabilities if combined with other weaknesses.
The plugin's vulnerability history shows a pattern of medium severity issues including missing authorization, SSRF, and CSRF. The recent vulnerability in July 2024, even though patched, reinforces the need for ongoing vigilance. The lack of robust authorization checks on entry points is a recurring theme in its past issues and is directly reflected in the static analysis. Despite some positive signals like the use of nonces and capability checks, the plugin's core architecture, particularly its handling of AJAX requests and potentially untrusted data, presents significant risks.
Key Concerns
- AJAX handlers without authentication checks
- Use of dangerous functions (unserialize, proc_open)
- Low percentage of properly escaped output
- Flows with unsanitized paths identified
- Vulnerability history with missing authorization
- Vulnerability history with SSRF
- Vulnerability history with CSRF
Seraphinite Post .DOCX Source Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Seraphinite Post .DOCX Source <= 2.16.9 - Missing Authorization
Seraphinite Post .DOCX Source <= 2.16.9 - Authenticated (Subscriber+) Server-Side Request Forgery
Seraphinite Post .DOCX Source <= 2.16.6 - Cross-Site Request Forgery
Seraphinite Post .DOCX Source Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Seraphinite Post .DOCX Source Attack Surface
AJAX Handlers 2
WordPress Hooks 41
Maintenance & Trust
Seraphinite Post .DOCX Source Maintenance & Trust
Maintenance Signals
Community Trust
Seraphinite Post .DOCX Source Alternatives
Categories to Tags Converter
wpcat2tag-importer
Convert existing categories to tags or tags to categories, selectively.
FG PrestaShop to WooCommerce
fg-prestashop-to-woocommerce
A plugin to migrate PrestaShop e-commerce solution to WooCommerce
Taxonomy Converter
taxonomy-converter
Copy or convert terms between taxonomies.
FG OpenCart to WooCommerce
fg-opencart-to-woocommerce
A plugin to migrate OpenCart e-commerce solution to WooCommerce
FG SPIP to WordPress
fg-spip-to-wp
A plugin to migrate categories, articles, news, and images from SPIP to WordPress
Seraphinite Post .DOCX Source Developer Profile
5 plugins · 61K total installs
How We Detect Seraphinite Post .DOCX Source
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/seraphinite-post-docx-source/css/style.css/wp-content/plugins/seraphinite-post-docx-source/css/admin-styles.css/wp-content/plugins/seraphinite-post-docx-source/js/frontend-script.js/wp-content/plugins/seraphinite-post-docx-source/js/admin-script.js/wp-content/plugins/seraphinite-post-docx-source/js/frontend-script.js/wp-content/plugins/seraphinite-post-docx-source/js/admin-script.jsseraphinite-post-docx-source/css/style.css?ver=seraphinite-post-docx-source/css/admin-styles.css?ver=seraphinite-post-docx-source/js/frontend-script.js?ver=seraphinite-post-docx-source/js/admin-script.js?ver=HTML / DOM Fingerprints
seraph-pds-frontend-containerseraph-pds-admin-container<!-- Seraphinite Post .DOCX Source Plugin Start --><!-- Seraphinite Post .DOCX Source Plugin End -->data-seraph-pds-post-iddata-seraph-pds-nonceseraphPDSFrontendseraphPDSAdmin/wp-json/seraph-pds/v1/save-post-data