
Category 2 Post Type Security & Risk Analysis
wordpress.org/plugins/category-to-custom-post-typeAllows you to move categories to custom post types and/or taxonomies.
Is Category 2 Post Type Safe to Use in 2026?
Generally Safe
Score 85/100Category 2 Post Type has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "category-to-custom-post-type" plugin, at version 0.1.5, presents a mixed security profile. On the positive side, its attack surface appears to be entirely protected by authentication checks, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper authorization. Furthermore, there are no recorded vulnerabilities (CVEs) for this plugin, suggesting a history of relatively secure development or limited scrutiny. This lack of historical vulnerabilities could indicate responsible coding practices or that the plugin hasn't been a target of significant public research.
However, the static analysis reveals several critical concerns. The presence of two SQL queries that do not utilize prepared statements is a significant risk, potentially opening the door to SQL injection vulnerabilities. Equally worrying is the complete lack of proper output escaping, with 0% of the 7 identified outputs being escaped. This makes the plugin highly susceptible to cross-site scripting (XSS) attacks, where malicious scripts could be injected into the site's output.
Despite the protected attack surface and clean vulnerability history, the identified code quality issues in SQL handling and output escaping are serious and require immediate attention. The plugin's strengths lie in its controlled entry points and lack of historical issues, but its weaknesses in input validation and output sanitization present immediate and exploitable risks.
Key Concerns
- SQL queries without prepared statements
- No output escaping
Category 2 Post Type Security Vulnerabilities
Category 2 Post Type Code Analysis
SQL Query Safety
Output Escaping
Category 2 Post Type Attack Surface
WordPress Hooks 2
Maintenance & Trust
Category 2 Post Type Maintenance & Trust
Maintenance Signals
Community Trust
Category 2 Post Type Alternatives
ReOrder Posts within Categories
reorder-post-within-categories
Enables manual ranking of post (and custom post) within taxonomy terms using a drag & drop grid interface.
Pretty Url
pretty-url
Description: Pretty URLs is a powerful WordPress plugin that lets you create clean, SEO-optimized custom URLs for any content type — including Posts, …
Taxonomy Tree Toggler
taxonomy-tree-toggler
Check all parent taxonomies on check, uncheck all sub-taxnomies on uncheck. Compatible with WordPress Gutenberg. Working with WordPress hierarchical …
Last Posts Category and Post Types
last-posts-category-and-post-types
You can configure the widget for show custom category posts, custom post types posts and what you image with that.
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Category 2 Post Type Developer Profile
5 plugins · 50 total installs
How We Detect Category 2 Post Type
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-to-custom-post-type/css/style.css/wp-content/plugins/category-to-custom-post-type/js/cats.jscategory-to-custom-post-type/js/cats.js?ver=HTML / DOM Fingerprints
new-cat-dd