
Tilda-publishing Security & Risk Analysis
wordpress.org/plugins/tilda-publishingExport html page from Tilda.cc for import to your WordPress site into post or page.
Is Tilda-publishing Safe to Use in 2026?
Generally Safe
Score 100/100Tilda-publishing has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "tilda-publishing" plugin v0.3.27 exhibits a mixed security posture. On the positive side, the plugin utilizes prepared statements for all SQL queries and has a decent number of capability checks. However, a significant concern is the presence of two AJAX handlers that lack proper authentication checks, representing a direct attack vector for unauthorized actions. Furthermore, the output escaping is only 44% proper, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not correctly sanitized before being displayed.
The vulnerability history shows one past CVE, which was medium severity and related to missing authorization. While there are no currently unpatched vulnerabilities, this pattern suggests a recurring weakness in authorization controls within the plugin. The taint analysis revealed no critical or high-severity unsanitized flows, which is a positive indicator. However, the combination of unprotected AJAX endpoints and insufficient output escaping, despite the absence of critical taint flows, means that an attacker could potentially exploit these weaknesses.
In conclusion, while the plugin demonstrates good practices in SQL handling and has no critical taint issues, the unprotected AJAX endpoints and the prevalence of unescaped output are significant security concerns that require immediate attention. The past vulnerability related to missing authorization further reinforces the need for robust access control in the plugin's entry points. Addressing these specific weaknesses would greatly improve the plugin's overall security. A score of 100 is a starting point, and deductions will be made for identified risks.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- One past medium severity CVE (Missing Authorization)
Tilda-publishing Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Tilda Publishing <= 0.3.23 - Missing Authorization
Tilda-publishing Release Timeline
Tilda-publishing Code Analysis
Output Escaping
Data Flow Analysis
Tilda-publishing Attack Surface
AJAX Handlers 13
WordPress Hooks 13
Scheduled Events 3
Maintenance & Trust
Tilda-publishing Maintenance & Trust
Maintenance Signals
Community Trust
Tilda-publishing Alternatives
Ghost
ghost
Export all your WordPress data to Ghost in a couple of clicks!
Addiction Recovery Connector
addiction-recovery-connector
The Addiction Recovery Connector plugin connects your WordPress site with the Addiction Recovery content publishing portal which allows us to easily s …
Published Posts Exporter
published-posts-exporter
Export published blog posts to CSV format with URLs, titles, content, tags, and categories. Supports both database queries and XML file processing.
Zenpost
zenpost
Delivering and managing your Zenpost content from your Zenpost account to your Wordpress site.
Export Assist
export-assist
A simple plugin that help you to easily export wordpress data to blogger in xml file.
Tilda-publishing Developer Profile
1 plugin · 700 total installs
How We Detect Tilda-publishing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tilda-publishing/tilda-publishing-admin.css/wp-content/plugins/tilda-publishing/tilda-publishing-admin.js/wp-content/plugins/tilda-publishing/tilda-publishing.css/wp-content/plugins/tilda-publishing/tilda-publishing.js/wp-content/plugins/tilda-publishing/tilda-publishing-admin.js/wp-content/plugins/tilda-publishing/tilda-publishing.jstilda-publishing/tilda-publishing-admin.css?ver=tilda-publishing/tilda-publishing-admin.js?ver=tilda-publishing/tilda-publishing.css?ver=tilda-publishing/tilda-publishing.js?ver=HTML / DOM Fingerprints
tilda-publishingdata-tilda-project-iddata-tilda-page-idtildaAdmintilda_project_idtilda_page_idtilda_sync_data/wp-json/tilda/v1/sync