
Add Script To Post Security & Risk Analysis
wordpress.org/plugins/add-script-to-postAdd custom script to a post by shortcode in post's content.
Is Add Script To Post Safe to Use in 2026?
Generally Safe
Score 100/100Add Script To Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The add-script-to-post plugin version 1.0 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) recorded, and the plugin does not utilize dangerous functions, perform file operations, or make external HTTP requests. All SQL queries are also handled with prepared statements. However, significant concerns arise from the lack of output escaping, with 100% of identified outputs not being properly escaped. This presents a substantial risk for cross-site scripting (XSS) vulnerabilities.
The static analysis reveals a single entry point via a shortcode, which, critically, has no capability checks or nonce verification. While the total attack surface is small and there are no AJAX or REST API endpoints without authentication, the unprotected shortcode is a major concern. The absence of taint analysis data (0 flows analyzed) and the lack of capability checks on the shortcode mean that any data processed or displayed by this shortcode could potentially be manipulated by unauthenticated users.
Given the clean vulnerability history, it's possible that the plugin hasn't been widely targeted or that the limited functionality hasn't exposed critical flaws yet. Nevertheless, the identified weaknesses, particularly unescaped output and the unprotected shortcode, create exploitable pathways. A strong conclusion is that while the plugin has a small attack surface and avoids some common pitfalls, the lack of output escaping and inadequate protection on its sole user-facing entry point (the shortcode) make it a moderate to high risk for XSS and potential content manipulation.
Key Concerns
- Unescaped output detected
- Shortcode without capability checks
- Shortcode without nonce checks
Add Script To Post Security Vulnerabilities
Add Script To Post Code Analysis
Output Escaping
Add Script To Post Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Add Script To Post Maintenance & Trust
Maintenance Signals
Community Trust
Add Script To Post Alternatives
Add Style To Post
add-style-to-post
Add custom style to a post by shortcode in post's content.
Material FAQ Manager
material-faq-manager
Display your faq and help page with latest material style design, Popout effect display answer.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Add Script To Post Developer Profile
24 plugins · 2K total installs
How We Detect Add Script To Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[script]