
Any CPT Listing Block Security & Risk Analysis
wordpress.org/plugins/any-cpt-listing-blockIn the Vision to Make Gutenberg for WordPress limitless with zero coding skill we have added this block to help users add latest any kind of posts or …
Is Any CPT Listing Block Safe to Use in 2026?
Generally Safe
Score 85/100Any CPT Listing Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "any-cpt-listing-block" plugin version 1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no recorded vulnerability history, suggesting a generally stable codebase. However, significant concerns arise from the static analysis. The plugin exposes a single REST API route that lacks any permission callbacks, creating an unprotected entry point into the application. Furthermore, a concerning 0% of its output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks across its limited attack surface also contributes to potential security weaknesses.
The lack of proper output escaping is the most immediate and severe risk, making it highly susceptible to XSS attacks where malicious scripts could be injected and executed in a user's browser. The unprotected REST API route, while a single point, is also a critical vulnerability as it allows unauthorized interaction with plugin functionalities. The absence of nonce and capability checks further exacerbates these issues by not enforcing necessary security measures to validate user actions and permissions. The plugin's current lack of known CVEs is a positive but does not negate the evident flaws in its current implementation.
Key Concerns
- Unprotected REST API route
- No output escaping
- No nonce checks
- No capability checks
Any CPT Listing Block Security Vulnerabilities
Any CPT Listing Block Release Timeline
Any CPT Listing Block Code Analysis
Output Escaping
Any CPT Listing Block Attack Surface
REST API Routes 1
WordPress Hooks 2
Maintenance & Trust
Any CPT Listing Block Maintenance & Trust
Maintenance Signals
Community Trust
Any CPT Listing Block Alternatives
IT Listings
it-listings
Custom Post Types and additional Functionality for IT Residence WordPress Theme
Blocksolid Snippets
blocksolid-snippets
Snippets functionality with a custom post type, shortcode and optional Gutenberg block.
Voxycure Framework
voxycure-framework
Create custom fields, blocks, and post types with no limitations. A flexible, free solution for building with custom data in WordPress.
Miramedia Event Manager for TEDx
miramedia-event-manager-for-tedx
Event management for TEDx organizers. Manage talks, speakers, and sponsors with custom Gutenberg blocks and advanced filtering.
Post Designer
post-designer
Post Designer is a WordPress plugin that adds two new Gutenberg blocks: Post List and Post Carousel. The Post List block allows you to display a list …
Any CPT Listing Block Developer Profile
13 plugins · 11K total installs
How We Detect Any CPT Listing Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/any-cpt-listing-block/build/index.css/wp-content/plugins/any-cpt-listing-block/build/index.js/wp-content/plugins/any-cpt-listing-block/build/index.jsHTML / DOM Fingerprints
acpt-mainacpt-front-screenacpt-rowacpt-block-itemacpt-gridacpt-listacpt-three-col/wp-json/wp/v2/available_types