
Zedna pending post indicator and notifier Security & Risk Analysis
wordpress.org/plugins/zedna-pending-post-indicator-and-notifierDisplay number of posts waiting for approval in administration. Send an email about waiting approval, approved/rejected post.
Is Zedna pending post indicator and notifier Safe to Use in 2026?
Generally Safe
Score 85/100Zedna pending post indicator and notifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the "zedna-pending-post-indicator-and-notifier" v1.0 plugin exhibits a generally good security posture. The plugin has a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed. Crucially, there are no identified entry points without authentication checks. The code also demonstrates good practices by not utilizing dangerous functions, performing file operations, or making external HTTP requests. All SQL queries are prepared, and there are some nonce checks present.
However, there are areas for improvement. The most significant concern is the low percentage of properly escaped output (36%). This indicates a potential risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. While no critical or high-severity taint flows were found, this low output escaping rate leaves room for such issues to arise. The lack of capability checks is also a concern, as it suggests that certain actions might not be properly restricted by user roles.
The plugin's vulnerability history is clean, with no recorded CVEs. This suggests a proactive approach to security by the developers or that the plugin has not been a target of significant exploitation. However, this absence of history should not lead to complacency. The identified weakness in output escaping, coupled with the lack of capability checks, represents potential vulnerabilities that could be exploited. Overall, while the plugin benefits from a small attack surface and good SQL handling, the inadequate output escaping and missing capability checks warrant attention to improve its security.
Key Concerns
- Low output escaping percentage
- No capability checks
Zedna pending post indicator and notifier Security Vulnerabilities
Zedna pending post indicator and notifier Code Analysis
Output Escaping
Data Flow Analysis
Zedna pending post indicator and notifier Attack Surface
WordPress Hooks 3
Maintenance & Trust
Zedna pending post indicator and notifier Maintenance & Trust
Maintenance Signals
Community Trust
Zedna pending post indicator and notifier Alternatives
Post Status Notifier Lite
post-status-notifier-lite
Notify on every post change: Flexible rules, custom placeholders and support for all post types and taxonomies.
AffiliateWP – Force Pending Referrals
affiliatewp-force-pending-referrals
Force all referrals to a "pending" status.
Pending Status
pending-status
Get notified when your site has posts pending review.
Subscribe2 – Form, Email Subscribers & Newsletters
subscribe2
Sends a list of subscribers an email notification when you publish new posts.
Archive Content with Archived Post Status
archived-post-status
Use an "Archived" status to unpublish content without having to trash it.
Zedna pending post indicator and notifier Developer Profile
15 plugins · 570 total installs
How We Detect Zedna pending post indicator and notifier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
update-pluginsplugin-count NOTE: Using the same CSS classes as the plugin updates count, it will match your admin color theme just fine.id="message"class="updated fade"id="review"id="pendingdiv"id="reviewdiv"id="notifier"+3 more