
Better Posts Plus Security & Risk Analysis
wordpress.org/plugins/better-posts-plusThe simplest way to change posts order (and more!) to create your own style!
Is Better Posts Plus Safe to Use in 2026?
Generally Safe
Score 85/100Better Posts Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'better-posts-plus' v0.9.5 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate a responsible approach to database interactions, with 100% of SQL queries utilizing prepared statements and no dangerous functions or file operations being present. The lack of external HTTP requests also contributes positively to its security.
However, a critical area of concern is the extremely low percentage (6%) of properly escaped output. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where unescaped data could be injected into the page rendered by the plugin. While taint analysis and vulnerability history show no current issues, this widespread output escaping deficiency is a significant weakness that could be easily exploited if an attacker can influence the data being outputted. The absence of nonce and capability checks, while not directly exploitable without entry points, suggests potential future vulnerabilities if entry points are introduced without corresponding security checks.
In conclusion, while the plugin has strong foundations in terms of limiting attack vectors and secure database handling, the severe deficiency in output escaping presents a substantial and readily exploitable risk. The plugin's history of zero vulnerabilities is encouraging but does not negate the identified code-level weaknesses. Addressing the output escaping issue should be a top priority.
Key Concerns
- Low percentage of properly escaped output
- No capability checks found
- No nonce checks found
Better Posts Plus Security Vulnerabilities
Better Posts Plus Code Analysis
Output Escaping
Better Posts Plus Attack Surface
WordPress Hooks 4
Maintenance & Trust
Better Posts Plus Maintenance & Trust
Maintenance Signals
Community Trust
Better Posts Plus Alternatives
Simple Custom Post Order
simple-custom-post-order
Easily reorder posts, pages, custom post types, and taxonomies with intuitive drag-and-drop sorting in the WordPress admin.
Reorder Posts
metronet-reorder-posts
A simple and easy way to reorder your custom post types in WordPress.
Custom Category Post Order
custom-post-order-category
Order your post by category or custom post type by drag & drop interface.
Order Manager
order-manager
Adds order controls for posts and terms
Custom Reorder Manager
custom-reorder-manager
Reorder WordPress posts with drag & drop mechanism.
Better Posts Plus Developer Profile
1 plugin · 0 total installs
How We Detect Better Posts Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/better-posts-plus/css/style.css/wp-content/plugins/better-posts-plus/js/custom.js/wp-content/plugins/better-posts-plus/css/style.css?ver=/wp-content/plugins/better-posts-plus/js/custom.js?ver=HTML / DOM Fingerprints
rp-aimweb-settings-wrap<!-- IMPORTANT: The rest of the options will be displayed with next updates --><!-- IMPORTANT: The rest of the options will be displayed with next updates. Thanks for the patience --><!-- This is just a sample for now. --><!-- Your posts -->data-rp-aimweb-post-iddata-rp-aimweb-settingsrp_aimweb_data/wp-json/rp-aimweb/v1/settings/wp-json/rp-aimweb/v1/update-setting[better_posts_plus_list][better_posts_plus_slider]