
Writing On GitHub Security & Risk Analysis
wordpress.org/plugins/writing-on-githubA WordPress plugin to allow you writing on GitHub (or Jekyll site).
Is Writing On GitHub Safe to Use in 2026?
Generally Safe
Score 100/100Writing On GitHub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "writing-on-github" plugin v1.11 presents a mixed security posture. On the positive side, the plugin demonstrates strong security practices in several areas. It avoids dangerous functions, all SQL queries are properly prepared, and a high percentage of outputs are escaped, indicating a good awareness of common web vulnerabilities. Furthermore, the absence of any recorded vulnerabilities or CVEs in its history is a significant positive indicator of its security over time.
However, the static analysis reveals a critical weakness. The plugin exposes a single AJAX handler that lacks any authentication or capability checks. This unprotected entry point is a significant security concern, as it could be leveraged by unauthenticated users to interact with the plugin in unintended ways, potentially leading to various attacks depending on the handler's functionality. The absence of taint analysis results and a lack of known vulnerabilities do not negate this specific, identified risk.
In conclusion, while the plugin's developers have implemented good security practices in many aspects of the code, the unprotected AJAX handler represents a serious oversight. This single vulnerability dramatically increases the plugin's risk profile, outweighing the positive aspects of its security history and coding standards. Remediation of this unprotected endpoint should be the top priority.
Key Concerns
- AJAX handler without authentication/capability checks
Writing On GitHub Security Vulnerabilities
Writing On GitHub Code Analysis
Output Escaping
Writing On GitHub Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Writing On GitHub Maintenance & Trust
Maintenance Signals
Community Trust
Writing On GitHub Alternatives
WP GitHub Sync Meta
wp-github-sync-meta
A WordPress plugin to sync meta, tags and categories with a GitHub via wp-github-sync
PraisonAI Git Posts
praison-file-content-git
Load WordPress content from files (Markdown, JSON, YAML) without database writes, with Git-based version control.
Version Control Your Content
version-control-your-content
Provides an alternative to the native WP Revisions feature using Git services. Also works for Additional CSS and wp-admin Settings pages.
WP Document Revisions
wp-document-revisions
A document management and version control plugin for WordPress that allows teams of any size to collaboratively edit files and manage their workflow.
Github Embed
github-embed
Plugin that allows you to embed details from GitHub just by pasting in the URL as you would any other embed source. Currently supports:
Writing On GitHub Developer Profile
4 plugins · 60 total installs
How We Detect Writing On GitHub
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/writing-on-github/assets/css/style.css/wp-content/plugins/writing-on-github/assets/js/script.js/wp-content/plugins/writing-on-github/assets/js/script.jswriting-on-github/assets/css/style.css?ver=writing-on-github/assets/js/script.js?ver=HTML / DOM Fingerprints
data-wogh-post-idWritingOnGithub/wp-json/writing-on-github/v1/posts