
Simple Post Preview & Review Security & Risk Analysis
wordpress.org/plugins/simple-post-preview-reviewShare secure preview links, collect client feedback and approvals, receive edits - all without WordPress login.
Is Simple Post Preview & Review Safe to Use in 2026?
Generally Safe
Score 100/100Simple Post Preview & Review has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'simple-post-preview-review' plugin v1.0.0 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the code demonstrates good practices in other areas, such as a high percentage of prepared SQL statements and properly escaped output, the lack of authentication checks on 12 AJAX entry points creates a substantial attack surface. This means any unauthenticated user could potentially trigger these AJAX actions, leading to unintended consequences or further exploitation if vulnerabilities exist within those handlers.
The static analysis also reveals that all 12 identified entry points are unprotected, which is a critical finding. Fortunately, the absence of critical or high severity taint flows and a clean vulnerability history suggest that there are no known exploitable flaws at this time. The plugin also appears to have a good handle on dangerous functions, file operations, and external HTTP requests. However, the large number of unprotected AJAX handlers remains the most significant risk, overshadowing the otherwise positive code signals.
Key Concerns
- Large attack surface without auth
- All AJAX handlers lack authentication checks
Simple Post Preview & Review Security Vulnerabilities
Simple Post Preview & Review Release Timeline
Simple Post Preview & Review Code Analysis
SQL Query Safety
Output Escaping
Simple Post Preview & Review Attack Surface
AJAX Handlers 12
WordPress Hooks 15
Scheduled Events 1
Maintenance & Trust
Simple Post Preview & Review Maintenance & Trust
Maintenance Signals
Community Trust
Simple Post Preview & Review Alternatives
SiteHandoff
sitehandoff
Client handoff tool for agencies: manage reviewer access, collect per-page feedback, and run a countdown page while the site is in progress.
Atarim – Visual Feedback, Review & AI Collaboration
atarim-visual-collaboration
Make collecting feedback on WordPress sites MUCH faster and easier, with the visual collaboration tool used on over 120,000 websites worldwide.
Testimonial Customer Feedback
testimonial-maker
Display client testimonials with customizable layouts, slider effects, and responsive design. Simple setup with shortcode support.
Visual Feedback
visual-feedback
Visual Feedback enables you to provide feedback on your WordPress site by simply clicking and commenting.
Smooth Testimonials
smooth-testimonials
Smooth Testimonial is a powerful and user-friendly WordPress plugin designed to showcase client testimonials with style and ease.
Simple Post Preview & Review Developer Profile
4 plugins · 440 total installs
How We Detect Simple Post Preview & Review
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-post-preview-review/admin/css/metabox.css/wp-content/plugins/simple-post-preview-review/admin/js/metabox.js/wp-content/plugins/simple-post-preview-review/public/css/preview.css/wp-content/plugins/simple-post-preview-review/public/js/preview.js/wp-content/plugins/simple-post-preview-review/admin/js/metabox.js/wp-content/plugins/simple-post-preview-review/public/js/preview.jssimple-post-preview-review/admin/css/metabox.css?ver=simple-post-preview-review/admin/js/metabox.js?ver=simple-post-preview-review/public/css/preview.css?ver=simple-post-preview-review/public/js/preview.js?ver=HTML / DOM Fingerprints
sppr-metabox-contentsppr-status-sectionsppr-statussppr-status-approvedsppr-status-changes_requestedsppr-status-pendingsppr-status-datesppr-link-section+21 more<!-- Currently plugin version. --><!-- If this file is called directly, abort. --><!-- Admin metabox functionality --><!-- The code that runs during plugin activation. -->+88 moredata-post-iddata-nonceSPPR_MetaboxSPPR_FrontendSPPR_Admin/wp-json/sppr/v1/feedback/wp-json/sppr/v1/edit/wp-json/sppr/v1/settings