Zedna Auto Update Security & Risk Analysis

wordpress.org/plugins/zedna-auto-update

Allow automatic update for Core, Plugins, Themes, Translations and send a notification about that.

0 active installs v1.0 PHP + WP 5.0+ Updated Jun 26, 2020
autocorethemetranslationupdate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Zedna Auto Update Safe to Use in 2026?

Generally Safe

Score 85/100

Zedna Auto Update has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'zedna-auto-update' v1.0 plugin exhibits a strong security posture in several key areas. The static analysis reveals a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code demonstrates a commitment to secure data handling by exclusively using prepared statements for all SQL queries. The absence of dangerous functions, file operations, and external HTTP requests also contributes positively to its security. The lack of any recorded vulnerabilities in its history is a significant strength, suggesting a history of stable and secure development. However, a critical concern arises from the output escaping. With one total output identified and none being properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This oversight can allow malicious code to be injected into the plugin's output, potentially impacting users.

While the plugin is to be commended for its minimal attack surface and secure SQL practices, the unescaped output represents a tangible and potentially severe risk. The taint analysis showing zero flows, while positive, is limited by the absence of any identified entry points or potentially vulnerable code constructs. In conclusion, the plugin has demonstrated good security practices in its foundational code and history, but the unescaped output is a glaring weakness that needs immediate attention to prevent XSS attacks. Addressing this specific issue would significantly improve the plugin's overall security.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Zedna Auto Update Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Zedna Auto Update Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Zedna Auto Update Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuzedna-autoupdate.php:19
actionadmin_initzedna-autoupdate.php:92
actionplugins_loadedzedna-autoupdate.php:108
filterauto_update_corezedna-autoupdate.php:112
filterallow_dev_auto_core_updateszedna-autoupdate.php:113
filterallow_minor_auto_core_updateszedna-autoupdate.php:114
filterallow_major_auto_core_updateszedna-autoupdate.php:115
filterauto_update_themezedna-autoupdate.php:119
filterauto_update_pluginzedna-autoupdate.php:123
filterauto_update_translationzedna-autoupdate.php:127
filterauto_core_update_send_emailzedna-autoupdate.php:132
actionwp_loadedzedna-autoupdate.php:135
Maintenance & Trust

Zedna Auto Update Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 26, 2020
PHP min version
Downloads867

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Zedna Auto Update Developer Profile

Radek Mezulanik

15 plugins · 570 total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
2856 days
View full developer profile
Detection Fingerprints

How We Detect Zedna Auto Update

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrapform-table
Data Attributes
name="zedna_update_core"name="zedna_update_plugins"name="zedna_update_themes"name="zedna_update_translation"name="zedna_update_send_email"
FAQ

Frequently Asked Questions about Zedna Auto Update