SteemPress Security & Risk Analysis

wordpress.org/plugins/steempress

Stores your WordPress blogs on the hive blockchain where posts are rewarded with cryptocurrency as new audiences interacts with your content

100 active installs v2.6.3 PHP + WP 4.7+ Updated Mar 30, 2020
blockchainhivemonetizationwordpress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SteemPress Safe to Use in 2026?

Generally Safe

Score 85/100

SteemPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The SteemPress plugin version 2.6.3 exhibits a generally positive security posture based on the static analysis. There are no identified critical or high-severity taint flows, and the plugin avoids dangerous functions and file operations. Notably, all SQL queries are performed using prepared statements, a crucial security practice. However, a significant concern arises from the very low percentage of properly escaped output (7%). This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly into the HTML without sufficient sanitization. The absence of nonce checks, particularly given the lack of AJAX handlers in this version which might mitigate immediate risk, is still a point of caution for potential future development or if other entry points are discovered. The plugin's vulnerability history being clean is a strong positive indicator, suggesting a history of good security practices by the developers, but it does not negate the present output escaping issues. Overall, while the lack of known vulnerabilities and secure database practices are commendable, the widespread lack of output escaping represents a substantial risk that needs immediate attention.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks found
Vulnerabilities
None known

SteemPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SteemPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
87
7 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

7% escaped94 total outputs
Attack Surface

SteemPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
actionplugins_loadedincludes\class-steempress_sp.php:141
actionadmin_enqueue_scriptsincludes\class-steempress_sp.php:156
actionadmin_enqueue_scriptsincludes\class-steempress_sp.php:157
actionadmin_menuincludes\class-steempress_sp.php:159
actionwp_headincludes\class-steempress_sp.php:160
actionadmin_initincludes\class-steempress_sp.php:167
actiontransition_post_statusincludes\class-steempress_sp.php:168
actionpublish_future_postincludes\class-steempress_sp.php:169
filterbulk_actions-edit-postincludes\class-steempress_sp.php:172
filterbulk_actions-edit-postincludes\class-steempress_sp.php:173
filterhandle_bulk_actions-edit-postincludes\class-steempress_sp.php:174
filterhandle_bulk_actions-edit-postincludes\class-steempress_sp.php:175
actionadmin_noticesincludes\class-steempress_sp.php:176
actionadmin_noticesincludes\class-steempress_sp.php:177
actionsave_postincludes\class-steempress_sp.php:180
actionadd_meta_boxesincludes\class-steempress_sp.php:181
actionshow_user_profileincludes\class-steempress_sp.php:184
actionedit_user_profileincludes\class-steempress_sp.php:185
actionpersonal_options_updateincludes\class-steempress_sp.php:186
actionedit_user_profile_updateincludes\class-steempress_sp.php:187
actionwp_enqueue_scriptsincludes\class-steempress_sp.php:202
actionwp_enqueue_scriptsincludes\class-steempress_sp.php:203
filterthe_contentincludes\class-steempress_sp.php:204
Maintenance & Trust

SteemPress Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedMar 30, 2020
PHP min version
Downloads32K

Community Trust

Rating84/100
Number of ratings20
Active installs100
Developer Profile

SteemPress Developer Profile

howofr

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SteemPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/steempress/admin/css/steempress_sp-admin.css/wp-content/plugins/steempress/admin/js/steempress_sp-admin.js
Script Paths
/wp-content/plugins/steempress/admin/js/steempress_sp-admin.js
Version Parameters
steempress_sp-admin.css?ver=steempress_sp-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
steempress_sp-admin-wrap
HTML Comments
<!-- STEEMPRESS -->
Data Attributes
data-steempress-usernamedata-steempress-posting-keydata-steempress-rewarddata-steempress-tags
JS Globals
steempress_sp_admin_ajax_object
FAQ

Frequently Asked Questions about SteemPress