Tel-Publish – Плагин отправляет записи в телеграм instantview Security & Risk Analysis

wordpress.org/plugins/tel-publish

Просто й плагин что позволит вам публиковать новости или другие статьи в вашу группу телеграм

0 active installs v0.0.1 PHP 5.6+ WP 4.8+ Updated Oct 9, 2020
telegram
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Tel-Publish – Плагин отправляет записи в телеграм instantview Safe to Use in 2026?

Generally Safe

Score 85/100

Tel-Publish – Плагин отправляет записи в телеграм instantview has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "tel-publish" v0.0.1 plugin exhibits a strong overall security posture due to the absence of known vulnerabilities and a clean taint analysis. The code's adherence to secure coding practices, such as using prepared statements for all SQL queries, significantly reduces the risk of common database-related exploits. Furthermore, the lack of observed file operations and external HTTP requests (excluding one, which needs further investigation) limits the plugin's potential for introducing vulnerabilities in these areas. The static analysis also reveals a remarkably small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct entry points for attackers. This suggests a focus on secure development principles from the outset.

However, the plugin is not without its weaknesses. The most significant concern is the low percentage of properly escaped output (55%), indicating that approximately half of the plugin's output may be vulnerable to cross-site scripting (XSS) attacks. This is a critical area that needs immediate attention, as XSS can lead to session hijacking, defacement, and other malicious activities. Additionally, the complete absence of nonce checks and capability checks on the non-existent entry points (while seemingly positive from an attack surface perspective) means that if any entry points were to be added in the future without proper security measures, they would be entirely unprotected. The single external HTTP request also warrants investigation to ensure it is handled securely and does not introduce any unforeseen risks.

Given that there is no vulnerability history, it is difficult to draw patterns. However, the absence of past vulnerabilities combined with a relatively clean code audit (barring the output escaping issue) suggests that the developers are likely aware of security best practices. The plugin's current version is v0.0.1, which is very early. This can be a double-edged sword: it means fewer eyes have likely reviewed the code, but also that the developers have a prime opportunity to solidify its security foundation. The main takeaway is that while the core functionality appears robust, the handling of output must be prioritized to prevent XSS vulnerabilities.

Key Concerns

  • Low output escaping percentage
  • No nonce checks on potential entry points
  • No capability checks on potential entry points
  • One external HTTP request
Vulnerabilities
None known

Tel-Publish – Плагин отправляет записи в телеграм instantview Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Tel-Publish – Плагин отправляет записи в телеграм instantview Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

55% escaped11 total outputs
Attack Surface

Tel-Publish – Плагин отправляет записи в телеграм instantview Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionedit_postTelPublish.php:25
actiontrash_postTelPublish.php:26
actionadmin_menuTelPublish.php:27
actionadd_meta_boxesTelPublish.php:28
filtersanitize_option_tel_pub_tokenTelPublish.php:29
filtersanitize_option_tel_pub_chat_idTelPublish.php:30
filtersanitize_option_tel_pub_rhashTelPublish.php:31
filtersanitize_option_tel_pub_htmlTelPublish.php:32
Maintenance & Trust

Tel-Publish – Плагин отправляет записи в телеграм instantview Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 9, 2020
PHP min version5.6
Downloads917

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Tel-Publish – Плагин отправляет записи в телеграм instantview Developer Profile

pechenki

2 plugins · 5K total installs

82
trust score
Avg Security Score
91/100
Avg Patch Time
79 days
View full developer profile
Detection Fingerprints

How We Detect Tel-Publish – Плагин отправляет записи в телеграм instantview

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<label>Telegram message id <input type="text" disabled name="telpublishmessage" value=""><input type="checkbox" name="telpublish_is_send" /> Sync telegram chat?</label>
FAQ

Frequently Asked Questions about Tel-Publish – Плагин отправляет записи в телеграм instantview