
WP Print Friendly Security & Risk Analysis
wordpress.org/plugins/wp-print-friendlyExtends WordPress' template system to support printer-friendly templates. Works with permalink structures to support nice URLs.
Is WP Print Friendly Safe to Use in 2026?
Generally Safe
Score 99/100WP Print Friendly has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-print-friendly" plugin v0.6.4 exhibits a mixed security posture. On the positive side, static analysis reveals no detected dangerous functions, file operations, external HTTP requests, or SQL queries using prepared statements. The output escaping is also quite robust at 88%. However, a significant concern arises from the complete lack of nonce checks and capability checks across all entry points. While the static analysis shows no unprotected entry points, the absence of these fundamental security mechanisms is a critical oversight that could allow for various unauthorized actions if an attacker can find a way to trigger the plugin's functions.
The plugin's vulnerability history is also a point of concern. It has two known medium-severity CVEs, both related to Cross-Site Scripting (XSS). Although these vulnerabilities are reported as patched, the pattern of XSS issues in its history suggests a potential weakness in input sanitization, which might not have been fully addressed or could re-emerge in future versions. The last known vulnerability dates back to 2015, which could indicate it's no longer actively maintained or that past issues were not comprehensively remediated.
In conclusion, while the core code appears to handle basic security practices like prepared statements and output escaping reasonably well, the lack of nonce and capability checks on potential execution paths is a significant weakness. Coupled with past XSS vulnerabilities, this plugin carries a moderate risk, particularly for environments where security is paramount. Active maintenance and a thorough review of authorization mechanisms are recommended.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Two past medium severity CVEs (XSS)
- Over 10% of outputs unescaped
WP Print Friendly Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Print Friendly <= 0.6 - Cross-Site Scripting
WP Print Friendly <= 0.6 - Cross-Site Scripting
WP Print Friendly Code Analysis
Output Escaping
WP Print Friendly Attack Surface
WordPress Hooks 13
Maintenance & Trust
WP Print Friendly Maintenance & Trust
Maintenance Signals
Community Trust
WP Print Friendly Alternatives
WP-Print
wp-print
Displays a printable version of your WordPress blog's post/page.
BSK PDF Manager
bsk-pdf-manager
Manage your PDFs / documents by category, can be display in list, columns and dropdown. Easy to embed a PDF contnet into post / page.
Save as PDF Plugin by PDFCrowd
save-as-pdf-by-pdfcrowd
Enable visitors to download your webpages as PDF with just one click.
wp-mpdf
wp-mpdf
Print Wordpress posts as PDF. Optional with Geshi highlighting.
PrinterCo Automatic Order Printing for WooCommerce
cloud-printing-for-woocommerce
Automatically print WooCommerce orders to your thermal POS printer-Perfect for restaurants, cafés, takeaways, and retail shops.
WP Print Friendly Developer Profile
12 plugins · 48K total installs
How We Detect WP Print Friendly
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-print-friendly/css/wp-print-friendly.css/wp-content/plugins/wp-print-friendly/js/wp-print-friendly.js/wp-content/plugins/wp-print-friendly/js/wp-print-friendly.jswp-print-friendly/css/wp-print-friendly.css?ver=wp-print-friendly/js/wp-print-friendly.js?ver=HTML / DOM Fingerprints
print_linkdata-print-optionswp_print_friendly_options[print_friendly]