YetiLabs Post Alerts for Slack Security & Risk Analysis

wordpress.org/plugins/yetilabs-post-alerts-for-slack

Send Slack messages when posts are published in specific categories, using configurable rules (category → channel → message template).

0 active installs v3.9.0 PHP 7.4+ WP 6.0+ Updated Dec 27, 2025
categoriesnotificationspostspublishingslack
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YetiLabs Post Alerts for Slack Safe to Use in 2026?

Generally Safe

Score 100/100

YetiLabs Post Alerts for Slack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "yetilabs-post-alerts-for-slack" v3.9.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs, coupled with a clean taint analysis and a lack of dangerous functions or raw SQL queries, is highly encouraging. The plugin also demonstrates good practices by implementing capability checks and nonce checks where relevant, and correctly utilizing prepared statements for its SQL operations. The plugin's code signals show a good degree of output escaping, with only a small percentage of outputs potentially not being properly sanitized, which is a minor concern but not a critical one.

However, the presence of two external HTTP requests warrants a closer look, as these could potentially be points of vulnerability if not handled securely. While no critical or high-severity issues were found in the taint analysis, it's important to note that only two flows were analyzed, which might not represent the entire plugin's functionality. The overall lack of reported vulnerabilities in its history is a significant strength, suggesting a commitment to security by the developers or a history of minor issues that were promptly addressed. Despite the minor concerns regarding unescaped output and external HTTP requests, the plugin appears to be relatively secure for its current version.

Key Concerns

  • External HTTP requests without explicit security checks
  • Some outputs not properly escaped
Vulnerabilities
None known

YetiLabs Post Alerts for Slack Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

YetiLabs Post Alerts for Slack Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
54 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

77% escaped70 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ylps_handle_save_settings (yetilabs-post-alerts-for-slack.php:198)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

YetiLabs Post Alerts for Slack Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuyetilabs-post-alerts-for-slack.php:164
actionadmin_enqueue_scriptsyetilabs-post-alerts-for-slack.php:183
actionadmin_post_ylps_save_settingsyetilabs-post-alerts-for-slack.php:256
actionsave_postyetilabs-post-alerts-for-slack.php:418
actiontransition_post_statusyetilabs-post-alerts-for-slack.php:432
actionpublish_postyetilabs-post-alerts-for-slack.php:445
Maintenance & Trust

YetiLabs Post Alerts for Slack Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 27, 2025
PHP min version7.4
Downloads100

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

YetiLabs Post Alerts for Slack Developer Profile

andreiavram

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YetiLabs Post Alerts for Slack

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yetilabs-post-alerts-for-slack/assets/js/admin-settings.js
Script Paths
/wp-content/plugins/yetilabs-post-alerts-for-slack/assets/js/admin-settings.js

HTML / DOM Fingerprints

Data Attributes
data-ylps-add-ruledata-ylps-remove-ruledata-ylps-rule-index
JS Globals
ylps_settings
FAQ

Frequently Asked Questions about YetiLabs Post Alerts for Slack