
WP Publication Archive Security & Risk Analysis
wordpress.org/plugins/wp-publication-archiveAllows users to upload, manage, search, and download publications, documents, and similar content (PDF, Power-Point, etc.).
Is WP Publication Archive Safe to Use in 2026?
Use With Caution
Score 63/100WP Publication Archive has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-publication-archive plugin version 3.0.1 exhibits a mixed security posture. On the positive side, the static analysis indicates a relatively small attack surface with no identified AJAX handlers or REST API routes exposed without authentication. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are all good security practices. However, significant concerns arise from the output escaping, where only 25% of outputs are properly escaped, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks, coupled with no taint analysis results, further compounds these concerns by indicating a lack of robust input validation and authorization mechanisms at key entry points.
The vulnerability history for this plugin is particularly alarming. With one unpatched medium severity CVE attributed to Cross-Site Scripting (XSS), and the last vulnerability occurring in the near future (2025-09-05), it indicates a recurring pattern of XSS issues and a lack of timely patching. This suggests that while the developers might be aware of some security issues, they are not consistently addressing them effectively or promptly. The current version also shows signs of unaddressed XSS potential in the static analysis due to poor output escaping. The lack of taint analysis data is also concerning as it might mean that comprehensive taint analysis was not performed, or that if it was, it failed to identify any issues, which contrasts with the identified XSS vulnerability history and poor output escaping.
In conclusion, while the plugin demonstrates some strengths in secure SQL handling and a limited attack surface, the high percentage of unescaped output and the presence of an unpatched XSS vulnerability, along with the complete lack of nonce and capability checks, present a significant risk. The recurring nature of XSS vulnerabilities indicates a need for more rigorous security development practices, particularly around input sanitization and output escaping, and a commitment to prompt patching.
Key Concerns
- Unpatched CVE: Medium severity XSS
- Poor output escaping (75% not escaped)
- 0 Nonce checks
- 0 Capability checks
- No taint analysis performed or reported
WP Publication Archive Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Publication Archive <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Publication Archive Code Analysis
Output Escaping
WP Publication Archive Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
WP Publication Archive Maintenance & Trust
Maintenance Signals
Community Trust
WP Publication Archive Alternatives
Document Gallery – Display PDF Gallery from Many Folders
catfolders-document-gallery
Display WordPress PDF gallery and file gallery from folder. Comes with a clean, searchable & sortable list/grid layout.
PDF Embedder
pdf-embedder
Seamlessly embed PDFs into your content, with customizations and intelligent responsive resizing, and no third-party services or iframes.
Download Manager
download-manager
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more
embedpress
EmbedPress lets you embed videos, pages, social feeds, embed PDF 3D flipbooks & other content on WordPress without coding & enhance storytelling.
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution
file-manager-advanced
Use Advanced File Manager to manage WordPress files, create archives, and build document libraries—all directly from your WordPress dashboard!
WP Publication Archive Developer Profile
6 plugins · 2K total installs
How We Detect WP Publication Archive
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-publication-archive/css/archive.css/wp-content/plugins/wp-publication-archive/css/single-publication.css/wp-content/plugins/wp-publication-archive/js/archive.js/wp-content/plugins/wp-publication-archive/js/single-publication.js/wp-content/plugins/wp-publication-archive/js/archive.js/wp-content/plugins/wp-publication-archive/js/single-publication.jswp-publication-archive/css/archive.css?ver=wp-publication-archive/css/single-publication.css?ver=wp-publication-archive/js/archive.js?ver=wp-publication-archive/js/single-publication.js?ver=HTML / DOM Fingerprints
archive-headerarchive-titlewp-publication-archive-item-thumbnailpublication-downloadsedit-linkdata-post-id[wp-publication-archive]