Skylark VKontakte Group Wall Publisher Security & Risk Analysis

wordpress.org/plugins/vkontakte-group-wall-publisher

Автоматическая публикация обновлений блога на стене группы ВКонтакте.

10 active installs v0.4.6.0 PHP + WP 2.5+ Updated Mar 3, 2012
%d0%b2%d0%ba%d0%be%d0%bd%d1%82%d0%b0%d0%ba%d1%82%d0%b5%d0%ba%d1%80%d0%be%d1%81%d1%81%d0%bf%d0%be%d1%81%d1%82%d0%b8%d0%bd%d0%b3group-wallpublish-eventvkontakte
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Skylark VKontakte Group Wall Publisher Safe to Use in 2026?

Generally Safe

Score 85/100

Skylark VKontakte Group Wall Publisher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "vkontakte-group-wall-publisher" plugin v0.4.6.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates excellent practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerabilities or CVEs. This suggests a history of responsible development and maintenance.

However, significant concerns arise from the static analysis. The complete lack of output escaping is a critical weakness, indicating that any data processed by the plugin and displayed to users could be susceptible to cross-site scripting (XSS) attacks. Additionally, the taint analysis reveals two flows with unsanitized paths, which, while not flagged as critical or high severity, represent potential vulnerabilities that could be exploited if not addressed. The absence of nonce checks and capability checks on any potential entry points, although currently listed as zero, is a latent risk if the attack surface were to expand or if these checks were inadvertently removed.

In conclusion, while the plugin benefits from a clean vulnerability history and secure database practices, the unescaped output and unsanitized taint flows are substantial risks that need immediate attention. The lack of protective measures like nonce and capability checks on current entry points (though zero) also warrants vigilance. Addressing the output escaping and taint flow issues should be the top priority to improve its overall security.

Key Concerns

  • 0% output escaping
  • Unsanitized paths in taint flows
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Skylark VKontakte Group Wall Publisher Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Skylark VKontakte Group Wall Publisher Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
skylark_vkontakte_wall_post_options_page (vkontaktegroupwallpost.php:165)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Skylark VKontakte Group Wall Publisher Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_initvkontaktegroupwallpost.php:28
actionsave_postvkontaktegroupwallpost.php:30
actionsave_pagevkontaktegroupwallpost.php:31
actionpending_to_publishvkontaktegroupwallpost.php:392
actiondraft_to_publishvkontaktegroupwallpost.php:393
actionnew_to_publishvkontaktegroupwallpost.php:394
actionpublish_postvkontaktegroupwallpost.php:396
actionadmin_menuvkontaktegroupwallpost.php:399
Maintenance & Trust

Skylark VKontakte Group Wall Publisher Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedMar 3, 2012
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Skylark VKontakte Group Wall Publisher Developer Profile

oleglark

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Skylark VKontakte Group Wall Publisher

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
vkontakte-group-wall-publisher/vgwp_script.js
Version Parameters
vkontakte-group-wall-publisher/vgwp_script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Post/Page should be Published first! -->
Data Attributes
data-vgwp-iddata-vgwp-publish
JS Globals
VKvgwp_postToWall
FAQ

Frequently Asked Questions about Skylark VKontakte Group Wall Publisher