
AutoListicle: Automatically Update Numbered List Articles Security & Risk Analysis
wordpress.org/plugins/autolisticle-automatically-update-numbered-list-articlesAutomatically keep your numbered lists in articles displaying the correct number by using this shortcode [auto-list-number].
Is AutoListicle: Automatically Update Numbered List Articles Safe to Use in 2026?
Generally Safe
Score 99/100AutoListicle: Automatically Update Numbered List Articles has a strong security track record. Known vulnerabilities have been patched promptly.
The Autolisticle plugin, version 1.3, exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, proper handling of SQL queries with prepared statements, and complete output escaping are excellent indicators of good development practices. Furthermore, the lack of file operations, external HTTP requests, and the absence of critical or high-severity taint flows suggest a relatively clean codebase from a direct exploitation standpoint.
However, a significant concern arises from the plugin's vulnerability history. The presence of a known CVE, even if currently patched, indicates a past weakness. The fact that the last vulnerability was a medium-severity Cross-Site Scripting (XSS) issue is particularly noteworthy, as XSS vulnerabilities can be exploited in various ways to compromise user sessions or deface websites. While the current analysis doesn't reveal exploitable flaws, this history warrants vigilance.
A point of consideration is the complete absence of nonce checks and capability checks, coupled with a lack of authentication checks on the identified entry points (shortcodes). While the static analysis indicates no unprotected entry points (likely meaning WordPress's default checks are in place for shortcodes), the explicit lack of custom nonce/capability checks could still introduce subtle risks if the shortcode logic is complex or relies on user-provided data that isn't rigorously validated within the shortcode's execution context. In conclusion, the plugin has commendable coding practices, but the past XSS vulnerability and the absence of explicit security checks on its entry points are areas that require attention.
Key Concerns
- Past Medium severity XSS vulnerability
- No nonce checks on entry points
- No capability checks on entry points
AutoListicle: Automatically Update Numbered List Articles Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AutoListicle: Automatically Update Numbered List Articles <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
AutoListicle: Automatically Update Numbered List Articles Code Analysis
Output Escaping
AutoListicle: Automatically Update Numbered List Articles Attack Surface
Shortcodes 3
WordPress Hooks 1
Maintenance & Trust
AutoListicle: Automatically Update Numbered List Articles Maintenance & Trust
Maintenance Signals
Community Trust
AutoListicle: Automatically Update Numbered List Articles Alternatives
listicle
listicle
Listicle plugin, lets you create paginated lists where every item in a bulleted list generates a post
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
AutoListicle: Automatically Update Numbered List Articles Developer Profile
5 plugins · 15K total installs
How We Detect AutoListicle: Automatically Update Numbered List Articles
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/autolisticle-automatically-update-numbered-list-articles/style.css/wp-content/plugins/autolisticle-automatically-update-numbered-list-articles/script.js/wp-content/plugins/autolisticle-automatically-update-numbered-list-articles/script.jsautolisticle-automatically-update-numbered-list-articles/style.css?ver=autolisticle-automatically-update-numbered-list-articles/script.js?ver=HTML / DOM Fingerprints
auto-list-numbernamewrapperbeforeafterdisplaystart+1 moreauto_list_numbersauto_list_totals[auto-list-number]