
Category Post Security & Risk Analysis
wordpress.org/plugins/category-postAdd "New Post" by Categories in admin menu.
Is Category Post Safe to Use in 2026?
Generally Safe
Score 85/100Category Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "category-post" plugin v0.8 exhibits a mixed security posture. On the positive side, the static analysis reveals no obvious high-risk elements like dangerous functions, raw SQL queries, file operations, or external HTTP requests. The absence of known vulnerabilities in its history is also a strong indicator of a well-maintained or less complex plugin. However, several areas raise significant concerns. The fact that 100% of outputs are not properly escaped presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of taint flows with unsanitized paths. While the number of flows is low (2), the fact that they are unsanitized is a critical weakness. Furthermore, the complete lack of capability checks and nonce checks on potential entry points (even though the static analysis reports zero entry points in this specific scan) suggests a potential for privilege escalation or unauthorized actions if any new entry points are introduced or if the static analysis missed something. The plugin's strengths lie in its apparent avoidance of common direct injection vulnerabilities, but its output handling and lack of robust authorization checks are significant weaknesses.
Key Concerns
- Unsanitized output detected
- Taint flows with unsanitized paths
- No capability checks found
- No nonce checks found
Category Post Security Vulnerabilities
Category Post Release Timeline
Category Post Code Analysis
Output Escaping
Data Flow Analysis
Category Post Attack Surface
WordPress Hooks 6
Maintenance & Trust
Category Post Maintenance & Trust
Maintenance Signals
Community Trust
Category Post Alternatives
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
No Category Base (WPML)
no-category-base-wpml
This plugin removes the mandatory 'Category Base' from your category permalinks. It's compatible with WPML.
Pages with category and tag
pages-with-category-and-tag
Add Categories and Tags to Pages.
Remove Category URL – Remove 'category' base from category permalinks
remove-category-url
Remove Category URL strips the /category/ base from your category URLs, turning something like /category/my-category/ into simply /my-category/.
Categories Images
categories-images
The Categories Images is a Wordpress plugin allow you to add image to category, tag or custom taxonomy.
Category Post Developer Profile
23 plugins · 216K total installs
How We Detect Category Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-post/scripts.jsscripts.js