
Social Publisher Security & Risk Analysis
wordpress.org/plugins/social-publisherAuto-publish WordPress posts to LinkedIn — with AI rewriting, Brand Voice, and scheduling. For social media managers. GDPR-compliant.
Is Social Publisher Safe to Use in 2026?
Generally Safe
Score 100/100Social Publisher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The social-publisher plugin v1.8.1 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, utilizing prepared statements exclusively, and has a clean vulnerability history with no recorded CVEs. However, significant concerns arise from its attack surface. A substantial portion of its entry points, specifically 5 out of 7, lack authentication and permission checks. This includes 3 AJAX handlers and 2 REST API routes that are exposed without proper authorization mechanisms, creating a direct pathway for potential unauthorized actions if vulnerabilities exist within these handlers.
The static analysis shows no dangerous functions or taint flow issues, indicating that internally the code might be relatively safe from common injection vulnerabilities. Despite a high number of output operations, a concerning 31% are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if attacker-controlled data is rendered unescaped. The presence of numerous external HTTP requests (24) could also be a vector for attacks if not handled securely, though no specific vulnerabilities are indicated in the provided data.
Overall, the plugin's lack of past vulnerabilities is a positive sign, suggesting that the developers may have some security awareness. Nevertheless, the identified weaknesses in access control for several entry points present a notable risk. The unescaped output is also a concern that should be addressed. The plugin's strengths lie in its database query practices and lack of historical exploits, while its primary weakness lies in its unprotected attack surface.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Unescaped output
Social Publisher Security Vulnerabilities
Social Publisher Release Timeline
Social Publisher Code Analysis
SQL Query Safety
Output Escaping
Social Publisher Attack Surface
AJAX Handlers 5
REST API Routes 2
WordPress Hooks 52
Scheduled Events 2
Maintenance & Trust
Social Publisher Maintenance & Trust
Maintenance Signals
Community Trust
Social Publisher Alternatives
Manago AI & Leadoo AI
salesmanago
AI-powered Customer Engagement Platform for impact-hungry eCommerce marketing teams
ParrotPoster – Auto Post to Social Media
parrotposter
Auto post or selective post of news and products from the site to social networks (media) Facebook, Instagram, Telegram, VK, OK (autoposting, autopost …
AVIR Auto Post to X Ultimate
avir-autopost-to-x-ultimate
Automatically post your WordPress content to X (formerly Twitter) with advanced customization options and media support.
Devenia Autoposter for LinkedIn
devenia-autoposter-for-linkedin
Auto-post to LinkedIn with rotating images, algorithm-optimized formatting, and zero bloat.
NextBrill Autopost
nextbrill-autopost
AI-powered WordPress plugin that generates and publishes SEO-optimized blog posts using OpenAI. Add one post at a time, process it, then add the next.
Social Publisher Developer Profile
3 plugins · 40 total installs
How We Detect Social Publisher
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/social-publisher/includes/css/admin-style.css/wp-content/plugins/social-publisher/includes/css/public-style.css/wp-content/plugins/social-publisher/includes/js/social-publisher.js/wp-content/plugins/social-publisher/includes/js/social-publisher.jssocial-publisher/includes/css/admin-style.css?ver=social-publisher/includes/css/public-style.css?ver=social-publisher/includes/js/social-publisher.js?ver=HTML / DOM Fingerprints
social-publisher-settings-pagesocipu-admin-noticesocipu-linkedin-iconsocipu-post-settingssocipu-post-settings-fieldsocipu-post-settings-labelsocipu-post-settings-inputsocipu-metabox-linkedin<!-- SP DEBUG --><!-- SOCIAL PUBLISHER: Main Wrapper -->data-socipu-post-iddata-socipu-target-urnsocialPublishersocipu_admin_vars/wp-json/social-publisher/v1/authenticate/wp-json/social-publisher/v1/settings/wp-json/social-publisher/v1/post/wp-json/social-publisher/v1/license