WP Discord Post Plus – Supports Unlimited Channels Security & Risk Analysis

wordpress.org/plugins/wp-discord-post-plus

WP Discord Post Plus integrates with WordPress and WooCommerce (if installed) to send your new post and orders to discord channels.

800 active installs v1.0.2 PHP + WP 4.4+ Updated Apr 16, 2023
chatdiscordpostpublishserver
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEAug 15, 2025
Safety Verdict

Is WP Discord Post Plus – Supports Unlimited Channels Safe to Use in 2026?

Use With Caution

Score 63/100

WP Discord Post Plus – Supports Unlimited Channels has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Aug 15, 2025Updated 2yr ago
Risk Assessment

The "wp-discord-post-plus" plugin version 1.0.2 exhibits a mixed security posture. On the positive side, static analysis reveals a very small attack surface with zero identified entry points and no dangerous functions utilized. All SQL queries are properly prepared, and there are no file operations or external HTTP requests that appear to be a direct security concern within the analyzed code. However, a significant weakness lies in the output escaping, with less than half of the outputs being properly sanitized, presenting a potential risk of Cross-Site Scripting (XSS) vulnerabilities.

Taint analysis shows no critical or high-severity flows, which is a positive indicator. Yet, the absence of nonce checks on any entry points, coupled with only one capability check, suggests that authentication and authorization might not be consistently enforced across all plugin functionalities. The vulnerability history is a major red flag, with one unpatched medium-severity CVE, historically related to Cross-Site Request Forgery (CSRF). The presence of an unpatched vulnerability, even if medium severity, significantly elevates the risk profile.

In conclusion, while the plugin has some good security practices like prepared SQL statements and a minimal attack surface, the poor output escaping and the unpatched CSRF vulnerability are significant concerns. The lack of robust nonce and capability checks further exacerbates these issues, making the plugin a potential target for attackers. Addressing the output escaping and the unpatched CVE is paramount to improving its security.

Key Concerns

  • Unpatched CVE
  • Low output escaping percentage
  • No nonce checks on entry points
Vulnerabilities
1

WP Discord Post Plus – Supports Unlimited Channels Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-95550fd3-13e5-4341-8551-efe9070b0ada-wp-discord-post-plusmedium · 4.3Cross-Site Request Forgery (CSRF)

WP Discord Post Plus - Supports Unlimited Channels <= 1.0.2 - Cross-Site Request Forgery

Aug 15, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

WP Discord Post Plus – Supports Unlimited Channels Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
44
37 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

46% escaped81 total outputs
Attack Surface

WP Discord Post Plus – Supports Unlimited Channels Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_enqueue_scriptsincludes\class-wp-discord-enqueue-assets.php:21
actionadmin_enqueue_scriptsincludes\class-wp-discord-enqueue-assets.php:22
actionadd_meta_boxesincludes\class-wp-discord-metabox.php:21
actionsave_postincludes\class-wp-discord-metabox.php:22
actionpublish_postincludes\class-wp-discord-metabox.php:23
actionadmin_menuincludes\class-wp-discord-post-admin.php:21
actionadmin_initincludes\class-wp-discord-post-admin.php:22
actionadmin_initincludes\class-wp-discord-post-admin.php:23
actionsend_post_to_discordincludes\class-wp-discord-post-post.php:21
actionwoocommerce_process_product_metaincludes\class-wp-discord-post-woocommerce.php:22
actionwoocommerce_checkout_update_order_metaincludes\class-wp-discord-post-woocommerce.php:26
Maintenance & Trust

WP Discord Post Plus – Supports Unlimited Channels Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedApr 16, 2023
PHP min version
Downloads19K

Community Trust

Rating80/100
Number of ratings11
Active installs800
Developer Profile

WP Discord Post Plus – Supports Unlimited Channels Developer Profile

wptasker

3 plugins · 1K total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Discord Post Plus – Supports Unlimited Channels

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-discord-post-plus/assets/main.css/wp-content/plugins/wp-discord-post-plus/assets/main.js
Script Paths
/wp-content/plugins/wp-discord-post-plus/assets/main.js
Version Parameters
wp-discord-post-plus/assets/main.js?ver=

HTML / DOM Fingerprints

Data Attributes
id='wp_discord_metabox_send_flag'name='wp_discord_metabox_send_flag'id='wp_discord_metabox_mention_flag'name='wp_discord_metabox_mention_flag'name='wp_discord_metabox_override_channel'
FAQ

Frequently Asked Questions about WP Discord Post Plus – Supports Unlimited Channels