
WP-DraftsForFriends Security & Risk Analysis
wordpress.org/plugins/wp-draftsforfriendsNow you don't need to add friends as users to the blog in order to let them preview your drafts
Is WP-DraftsForFriends Safe to Use in 2026?
Generally Safe
Score 85/100WP-DraftsForFriends has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-draftsforfriends v1.0.2 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any recorded vulnerabilities, including critical or high severity ones, is a strong indicator of good security practices and a well-maintained codebase. The plugin also demonstrates robust use of security features, with a significant majority of SQL queries utilizing prepared statements and a good number of nonce and capability checks implemented.
However, there are areas that warrant attention. The most significant concern is the output escaping, where only 38% of outputs are properly escaped. This leaves a substantial portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not adequately sanitized before being displayed. While the taint analysis did not reveal any direct unsanitized paths or critical/high severity flows, the low percentage of proper output escaping means that the potential for XSS remains a significant risk.
Overall, the plugin's history of zero vulnerabilities is reassuring, suggesting the developers are diligent. The use of prepared statements and the presence of security checks are commendable. The primary weakness lies in the insufficient output escaping, which presents a notable risk of XSS. Addressing this would significantly strengthen the plugin's security.
Key Concerns
- Low percentage of properly escaped output
WP-DraftsForFriends Security Vulnerabilities
WP-DraftsForFriends Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-DraftsForFriends Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
WP-DraftsForFriends Maintenance & Trust
Maintenance Signals
Community Trust
WP-DraftsForFriends Alternatives
Public Post Preview
public-post-preview
Allow anonymous users to preview a draft of a post before it is published.
Secure Role-Restricted Draft Previews
secure-role-restricted-draft-previews
Generate secure, expiring preview URLs for drafts with role/user restrictions. Compatible with FSE, Block Themes, and Classic Themes.
GoSMTP – SMTP for WordPress
gosmtp
Send emails from your WordPress site using your preferred SMTP provider like Gmail, Outlook, AWS, Zoho, SMTP.com, Brevo (formerly Sendinblue), Mailgun …
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Site Mailer – SMTP Replacement, Email API Deliverability & Email Log
site-mailer
Effortlessly manage transactional emails with Site Mailer. High deliverability, logs and statistics, and no SMTP plugins needed.
WP-DraftsForFriends Developer Profile
20 plugins · 889K total installs
How We Detect WP-DraftsForFriends
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-draftsforfriends/css/draftsforfriends-admin.min.css/wp-content/plugins/wp-draftsforfriends/css/draftsforfriends-admin.css/wp-content/plugins/wp-draftsforfriends/js/draftsforfriends-admin.min.js/wp-content/plugins/wp-draftsforfriends/js/draftsforfriends-admin.js/wp-content/plugins/wp-draftsforfriends/js/draftsforfriends-admin.min.js/wp-content/plugins/wp-draftsforfriends/js/draftsforfriends-admin.jswp-draftsforfriends/css/draftsforfriends-admin.min.css?ver=wp-draftsforfriends/css/draftsforfriends-admin.css?ver=wp-draftsforfriends/js/draftsforfriends-admin.min.js?ver=wp-draftsforfriends/js/draftsforfriends-admin.js?ver=HTML / DOM Fingerprints
draftsForFriendsAdminL10n