
Additional Content Security & Risk Analysis
wordpress.org/plugins/additional-contentDisplay additional content before or after post content in single post pages.
Is Additional Content Safe to Use in 2026?
Generally Safe
Score 85/100Additional Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the 'additional-content' plugin version 1.3.0 exhibits a generally strong security posture. The absence of any identified attack surface entry points (AJAX, REST API, shortcodes, cron events) is a significant positive indicator, suggesting a limited exposure to external manipulation. Furthermore, the complete absence of known vulnerabilities, including critical and high severity ones, and the use of prepared statements for all SQL queries demonstrate good development practices. The presence of nonce and capability checks also contributes positively.
However, a notable concern arises from the output escaping. With 37 total outputs and only 19% properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that data processed and displayed by the plugin might not be sufficiently sanitized, allowing attackers to inject malicious scripts. While taint analysis shows no flows with unsanitized paths, this is based on zero flows analyzed, which might indicate an incomplete analysis or a very simple plugin.
In conclusion, the plugin benefits from a lack of known vulnerabilities and a controlled attack surface. The main weakness lies in the insufficient output escaping, which presents a tangible risk of XSS. Future development should prioritize addressing this output sanitization gap. The limited taint analysis is also a potential area for deeper investigation if the plugin's functionality warrants it.
Key Concerns
- Insufficient output escaping
Additional Content Security Vulnerabilities
Additional Content Code Analysis
Output Escaping
Additional Content Attack Surface
WordPress Hooks 19
Maintenance & Trust
Additional Content Maintenance & Trust
Maintenance Signals
Community Trust
Additional Content Alternatives
Toggle wpautop
toggle-wpautop
Easily disable the default wpautop filter on a post by post basis.
Safe Paste
safe-paste
Removes a lot of HTML tags from post and page content before inserting it to database. Preventing users to paste undesired HTML tags to content.
Default Content
default-content
Inserts customizable default HTML content into the WordPress editor when creating a new post or page.
Post Lock
post-lock
Post Lock prevents accidental updating or publishing of content by requiring a password to do either.
Nelio Content – Editorial Calendar & Social Media Auto-Posting
nelio-content
Editorial calendar and social media auto-posting for WordPress. Plan content, schedule shares, and grow reach with powerful automations.
Additional Content Developer Profile
6 plugins · 11K total installs
How We Detect Additional Content
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/additional-content/includes/assets/js/additional-content.min.js/wp-content/plugins/additional-content/includes/assets/js/additional-content.min.jsadditional-content/style.css?ver=additional-content/includes/assets/js/additional-content.min.js?ver=HTML / DOM Fingerprints
<!-- additional-content -->data-iddata-nonceac_additional_content[additional-content]