
WP Post Status Notifications Security & Risk Analysis
wordpress.org/plugins/wp-post-status-notificationsConfigure email notifications for post/page status changes.
Is WP Post Status Notifications Safe to Use in 2026?
Generally Safe
Score 85/100WP Post Status Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-post-status-notifications" v1.0 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerability history. This suggests a developer who is mindful of common pitfalls. However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, and critically, both lack any authentication or capability checks. This creates a direct path for unauthenticated users to interact with potentially sensitive plugin functionality, which is a major security risk. Furthermore, the low percentage of properly escaped output (31%) indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site's content.
Key Concerns
- AJAX handlers without auth checks
- Low output escaping percentage
WP Post Status Notifications Security Vulnerabilities
WP Post Status Notifications Code Analysis
Output Escaping
WP Post Status Notifications Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
WP Post Status Notifications Maintenance & Trust
Maintenance Signals
Community Trust
WP Post Status Notifications Alternatives
OneClickPublish
oneclickpublish
This is a very basic plugin to simple toggle the status of your posts between publish and post
Extra Post Pages Menu
extra-posts-pages-menu
Adds extra and individual menus for all available post/page statuses like drafts, pending, trash including count of number of posts in each status.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Duplicate Post
copy-delete-posts
Duplicate post
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
custom-facebook-feed
Formerly "Custom Facebook Feed". Display completely customizable Facebook feeds of a Facebook page. Supports Facebook oEmbeds.
WP Post Status Notifications Developer Profile
5 plugins · 41K total installs
How We Detect WP Post Status Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-post-status-notifications/css/wpps-admin-style.css/wp-content/plugins/wp-post-status-notifications/js/wpps-admin-script.js/wp-content/plugins/wp-post-status-notifications/js/wpps-admin-script.js/wp-content/plugins/wp-post-status-notifications/css/wpps-admin-style.css?ver=/wp-content/plugins/wp-post-status-notifications/js/wpps-admin-script.js?ver=HTML / DOM Fingerprints
nav-tabnav-tab-activewrapwppse_tabbed_contentdata-wp-post-status-notificationswpps_admin