
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher Security & Risk Analysis
wordpress.org/plugins/wp-scheduled-postsAutomate your WordPress content scheduling with a visual calendar, auto/manual schedulers, missed‑post handler, social sharing options & templates.
Is SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher Safe to Use in 2026?
Generally Safe
Score 98/100SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-scheduled-posts plugin, version 5.2.17, exhibits a mixed security posture. While it demonstrates good practices like a significant number of capability checks and a relatively high percentage of properly escaped outputs, there are notable areas of concern. The presence of one unprotected REST API route is a direct security risk, as it allows unauthenticated access to potentially sensitive functionality. Furthermore, the taint analysis indicates two flows with unsanitized paths, which, although not rated as critical or high severity, suggest potential avenues for injection attacks if exploited.
The plugin's vulnerability history is a significant red flag. With three known medium-severity CVEs, and one occurring very recently (2024-07-15), it indicates a pattern of security weaknesses that attackers have successfully exploited in the past. The types of vulnerabilities—Exposure of Sensitive Information, Missing Authorization, and Improper Authorization—are particularly concerning as they can lead to data breaches and unauthorized control of the website. The fact that all past vulnerabilities are currently patched is positive, but the recurring nature of these issues warrants caution.
In conclusion, while the code shows some positive security implementations, the unprotected REST API endpoint, the presence of unsanitized paths in taint analysis, and a history of medium-severity authorization and information exposure vulnerabilities collectively present a moderate to high risk. Users should be aware of these issues and ensure the plugin is updated to the latest version, and actively monitor for new security advisories.
Key Concerns
- Unprotected REST API route
- Taint flows with unsanitized paths
- History of 3 medium CVEs
- Recent vulnerability (2024-07-15)
- Common vulnerability types: auth/exposure
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
SchedulePress <= 5.1.3 - Unauthenticated Full Path Disclosure
SchedulePress <= 5.0.8 - Missing Authorization
SchedulePress <= 5.0.4 - Insufficient Authorization to Authenticated (Contributor+) Arbitrary Post Modifications
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher Attack Surface
AJAX Handlers 7
REST API Routes 5
WordPress Hooks 94
Scheduled Events 12
Maintenance & Trust
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher Maintenance & Trust
Maintenance Signals
Community Trust
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher Alternatives
Post Flow
post-flow
This plugin will schedule 'auto post checks' to publish new posts and/or recycle old posts automatically.
Social Sharing Plugin – Sassy Social Share
sassy-social-share
The Simplest and Optimized Social Share buttons. Facebook, X, Reddit, Pinterest, Whatsapp, Grok, ChatGPT, Gab, Gettr and over 100 more.
Wp Social Login and Register Social Counter
wp-social
Wp social lets you add social login, social counter, and social share buttons of different styles to your WordPress website.
Ocean Social Sharing
ocean-social-sharing
Website: https://oceanwp.org/ Support: https://oceanwp.org/support/ Documentation: https://docs.oceanwp.org/ Extensions: https://oceanwp.
Hubbub Lite – Fast, free social sharing and follow buttons
social-pug
Your content is worth sharing. Let's makes it easier!
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher Developer Profile
46 plugins · 4.0M total installs
How We Detect SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-scheduled-posts/assets/css/backend-style.css/wp-content/plugins/wp-scheduled-posts/assets/css/frontend-style.css/wp-content/plugins/wp-scheduled-posts/assets/css/schedule-calendar.css/wp-content/plugins/wp-scheduled-posts/assets/css/schedule-dashboard.css/wp-content/plugins/wp-scheduled-posts/assets/js/admin-script.js/wp-content/plugins/wp-scheduled-posts/assets/js/schedule-calendar.js/wp-content/plugins/wp-scheduled-posts/assets/js/schedule-dashboard.js/wp-content/plugins/wp-scheduled-posts/assets/js/schedule-editor.js/wp-content/plugins/wp-scheduled-posts/assets/js/admin-script.js/wp-content/plugins/wp-scheduled-posts/assets/js/schedule-calendar.js/wp-content/plugins/wp-scheduled-posts/assets/js/schedule-dashboard.js/wp-content/plugins/wp-scheduled-posts/assets/js/schedule-editor.jswp-scheduled-posts/assets/css/backend-style.css?ver=wp-scheduled-posts/assets/css/frontend-style.css?ver=wp-scheduled-posts/assets/css/schedule-calendar.css?ver=wp-scheduled-posts/assets/css/schedule-dashboard.css?ver=wp-scheduled-posts/assets/js/admin-script.js?ver=wp-scheduled-posts/assets/js/schedule-calendar.js?ver=wp-scheduled-posts/assets/js/schedule-dashboard.js?ver=wp-scheduled-posts/assets/js/schedule-editor.js?ver=HTML / DOM Fingerprints
wpsp-wrapschedulepress-dashboard-widgetschedulepress-calendar-wrapper<!--schedulepress-calendar-wrapper--><!--/schedulepress-calendar-wrapper--><!--schedulepress-dashboard-widget--><!--/schedulepress-dashboard-widget-->+4 moredata-wpsp-post-iddata-wpsp-datedata-wpsp-titledata-wpsp-schedule-typedata-wpsp-statusWPSP_Adminschedulepress_calendar_settingsschedulepress_calendar_posts