
WP Mercure Security & Risk Analysis
wordpress.org/plugins/wp-mercureAdd WordPress integration of Mercure protocol and add realtime post modification.
Is WP Mercure Safe to Use in 2026?
Generally Safe
Score 85/100WP Mercure has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-mercure plugin v0.1 exhibits a concerning security posture despite its apparent lack of past vulnerabilities and zero recorded CVEs. The static analysis reveals a significant concern with its attack surface, specifically one unprotected REST API route. This single entry point, lacking permission callbacks, presents a direct avenue for unauthorized access and manipulation if it handles any sensitive data or functionality. While the plugin demonstrates good practices in using prepared statements for SQL queries and a reasonable number of nonce checks, the low percentage of properly escaped output (17%) is a significant weakness. This suggests that data displayed to users or processed in certain ways might be vulnerable to cross-site scripting (XSS) attacks.
The absence of taint analysis results and a clean vulnerability history might indicate that the plugin has not been extensively scrutinized or that its functionality is limited, thus not attracting malicious attention. However, this should not be interpreted as a guarantee of security. The identified unprotected REST API route is a critical flaw that must be addressed, as it bypasses WordPress's robust permission system. The poor output escaping further exacerbates potential risks. The overall conclusion is that while the plugin avoids common pitfalls like raw SQL or outdated bundled libraries, its limited but critical unprotected entry point and widespread output escaping issues warrant immediate attention.
Key Concerns
- Unprotected REST API route
- Low percentage of properly escaped output
WP Mercure Security Vulnerabilities
WP Mercure Code Analysis
Output Escaping
WP Mercure Attack Surface
REST API Routes 1
WordPress Hooks 9
Maintenance & Trust
WP Mercure Maintenance & Trust
Maintenance Signals
Community Trust
WP Mercure Alternatives
Realtime Comments
realtime-comments
Accepted comments from users are added to pages in real-time, without need to refresh. Makes comments section work interactively, like a chatroom.
WD Live Posts Update
wd-live-posts-update
Live Post Updates is a powerful plugin for live updates of posts and custom post types, integrating schema.org for better SEO.
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
post-expirator
PublishPress Future can make scheduled changes to your content. You can unpublish posts, move posts to a new status, update the categories, and more.
Bulk Post Update Date
bulk-post-update-date
Change the Post Update date for all posts and pages in one click. This will help your blog in search engines and your blog will look alive.
Last Modified Timestamp
last-modified-timestamp
Adds the last modified time to the admin interface as well as a [last-modified] shortcode to use on the front-end.
WP Mercure Developer Profile
2 plugins · 300 total installs
How We Detect WP Mercure
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-mercure/assets/js/editor/features/live-post-admin.js/wp-content/plugins/wp-mercure/assets/js/features/live-post/subscribes.jsHTML / DOM Fingerprints
misc-pub-push-mercurewpmercure/wp-json/wpmercure/v1/livepost