
wp2d Auto Post Security & Risk Analysis
wordpress.org/plugins/wp2d-auto-postAuto-posting the announces of publishing posts to the Discord channel.
Is wp2d Auto Post Safe to Use in 2026?
Generally Safe
Score 85/100wp2d Auto Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp2d-auto-post plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with exposed attack surfaces is a significant positive. Furthermore, the adherence to prepared statements for all SQL queries demonstrates a commitment to preventing SQL injection vulnerabilities.
However, there are notable areas of concern. The extremely low percentage of properly escaped output (11%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is outputted to the browser without adequate sanitization or escaping could be exploited to inject malicious scripts. While there are no known CVEs or taint flows recorded, this is likely due to the limited attack surface and the absence of complex logic that would typically generate such issues in static analysis. The presence of external HTTP requests, while only one, also warrants careful consideration, as it could be a vector for Server-Side Request Forgery (SSRF) or other vulnerabilities if not handled securely.
In conclusion, while the plugin's minimal attack surface and secure database practices are commendable, the severe lack of output escaping poses a significant risk. The absence of past vulnerabilities is likely a byproduct of its limited functionality and attack surface rather than inherent robust security in all aspects. Prioritizing proper output escaping is crucial to mitigate the XSS risks. The single external HTTP request should also be reviewed for security implications.
Key Concerns
- Low output escaping percentage
- External HTTP request present
wp2d Auto Post Security Vulnerabilities
wp2d Auto Post Code Analysis
Output Escaping
wp2d Auto Post Attack Surface
WordPress Hooks 5
Maintenance & Trust
wp2d Auto Post Maintenance & Trust
Maintenance Signals
Community Trust
wp2d Auto Post Alternatives
WP Discord Post Plus – Supports Unlimited Channels
wp-discord-post-plus
WP Discord Post Plus integrates with WordPress and WooCommerce (if installed) to send your new post and orders to discord channels.
Social Media Auto Poster – Schedule & Publish to Buffer
wp-to-buffer
Automatically post and schedule your WordPress content to Facebook, X/Twitter, LinkedIn, Threads, Bluesky, and more social networks using Buffer.
Social Web Suite – Social Media Auto Post, Social Media Auto Publish
social-web-suite
Social media auto post, social media auto publish, schedule, share, and promote your new, and re-share your old posts to Instagram, X(Twitter), Facebo …
Post to Social Media – WordPress to Hootsuite
wp-to-hootsuite
Automatically share WordPress Pages, Posts or Custom Post Types to Facebook, Twitter and LinkedIn using your Hootsuite (hootsuite.com) account.
auto-post.io
auto-post-io
Connect auto-post.io to WordPress for seamless content automation.
wp2d Auto Post Developer Profile
2 plugins · 310 total installs
How We Detect wp2d Auto Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wp2d_do_autopostwp2d_metabox