
AMP Post Script Security & Risk Analysis
wordpress.org/plugins/amp-post-scriptModify the AMP plugin for WordPress
Is AMP Post Script Safe to Use in 2026?
Generally Safe
Score 85/100AMP Post Script has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "amp-post-script" plugin version 1.7.5 demonstrates a generally good security posture based on the provided static analysis. There are no identified critical or high-severity code signals like dangerous functions, raw SQL queries, or external HTTP requests. The absence of known CVEs and past vulnerabilities further contributes to this positive assessment. However, a significant concern arises from the output escaping, where only 33% of the 18 identified outputs are properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without adequate sanitization, especially given the presence of a shortcode which is a potential entry point.
While the attack surface appears minimal with only one shortcode and no unprotected AJAX handlers or REST API routes, the lack of proper output escaping presents a tangible risk. The absence of nonce checks and capability checks is less concerning in this specific instance due to the limited attack surface and lack of auth bypass vulnerabilities identified, but it's a general good practice that is missing. Overall, the plugin is built on a solid foundation with no glaring vulnerabilities, but the output escaping issue requires attention to mitigate potential XSS risks.
Key Concerns
- Low output escaping percentage
AMP Post Script Security Vulnerabilities
AMP Post Script Code Analysis
Output Escaping
AMP Post Script Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
AMP Post Script Maintenance & Trust
Maintenance Signals
Community Trust
AMP Post Script Alternatives
Easy UTM Builder
easy-utm-builder
Easy to build trackable URLs with UTM parameters in Bulk (complete site or specific post type) for Google Analytics!
Musopress Discography
musopress-discography
Creates a Discography Custom Post Type and allows you to import your albums from Bandcamp.
Customer Referral Program | Refer a Friend Software
invitereferrals-customer-referral-program
Design and launch customer referral campaigns within minutes in Wordpress.
Diller Loyalty
diller-loyalty
Diller Loyalty platform integration plugin for seamless membership engagement. Manages points, coupons and benefits and integrates with WC orders.
AMP by Zaenu
amp-by-zaenu
Get your AMP (Accelarated Mobile Project) instantly!
AMP Post Script Developer Profile
2 plugins · 50 total installs
How We Detect AMP Post Script
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/amp-post-script/includes/ps-header-bar.php/wp-content/plugins/amp-post-script/includes/ps-header.php/wp-content/plugins/amp-post-script/includes/custom-styles.phphttps://cdn.ampproject.org/v0/amp-analytics-0.1.jsHTML / DOM Fingerprints
related-posts-titlerelated-postscustom-element="amp-analytics"id="analytics1"<p style="text-align:right;"><a class="button" href="">View More Info →</a></p>