
Admin Starred Posts Security & Risk Analysis
wordpress.org/plugins/admin-starred-postsMark posts, pages and custom posts in your WordPress admin; pretty similar to the stars feature in Gmail.
Is Admin Starred Posts Safe to Use in 2026?
Generally Safe
Score 85/100Admin Starred Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "admin-starred-posts" plugin v2.5.0 exhibits a concerning security posture due to a significant lack of authorization checks on its entry points. While the plugin does not appear to contain inherently dangerous functions, perform file operations, or make external HTTP requests, its single AJAX handler lacks any form of authentication or capability check. This means any user, even unauthenticated ones, can potentially trigger this handler, creating a substantial attack surface. Furthermore, the static analysis indicates a low percentage of properly escaped output, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care. The absence of any recorded vulnerabilities in its history is positive, suggesting a lack of exploitable flaws to date. However, this does not mitigate the immediate risks presented by the unprotected AJAX endpoint and the potentially unescaped output, which are significant weaknesses that require immediate attention.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
Admin Starred Posts Security Vulnerabilities
Admin Starred Posts Code Analysis
Output Escaping
Admin Starred Posts Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
Admin Starred Posts Maintenance & Trust
Maintenance Signals
Community Trust
Admin Starred Posts Alternatives
Post Descriptions
post-descriptions
A lightweight WordPress plugin that lets you add quick descriptions or personal notes to your posts and pages — perfect for reminders, to-do's, o …
WP Admin UI Customize
wp-admin-ui-customize
Customize the management screen UI.
LH Archived Post Status
lh-archived-post-status
Allows posts and pages to be archived so you can remove content from the main loop and feed without having to trash it.
HiFi (Head Injection, Foot Injection)
hifi
HiFi is a head and foot injection plugin. It allows you to inject code into the head and foot areas of your posts and pages on a per-page basis.
Sortable Word Count Reloaded
sortable-word-count-reloaded
Adds a sortable column to the posts and pages admin list with the word count of each page/post.
Admin Starred Posts Developer Profile
1 plugin · 400 total installs
How We Detect Admin Starred Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-starred-posts/js/starred-posts.js/wp-content/plugins/admin-starred-posts/js/settings.js/wp-content/plugins/admin-starred-posts/css/main.css/wp-content/plugins/admin-starred-posts/js/starred-posts.js/wp-content/plugins/admin-starred-posts/js/settings.jsadmin-starred-posts/js/starred-posts.js?ver=admin-starred-posts/js/settings.js?ver=admin-starred-posts/css/main.css?ver=HTML / DOM Fingerprints
ino-starred-column-headerino-star-clickableino-starc%dino-star-postid-%ddata-stars_idsdata-star_iddata-post_id