
Checklist in Post Security & Risk Analysis
wordpress.org/plugins/checklist-in-postAllow creating checklists in posts based on bulleted list.
Is Checklist in Post Safe to Use in 2026?
Generally Safe
Score 85/100Checklist in Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "checklist-in-post" plugin v1.1.3 presents a generally good security posture, primarily due to the absence of known vulnerabilities and the use of prepared statements for all SQL queries. The static analysis reveals no critical security flaws such as dangerous functions, file operations, or external HTTP requests. Furthermore, there are no recorded CVEs, indicating a history of secure development or prompt patching.
However, a significant concern arises from the lack of output escaping. With three output points identified and none properly escaped, there is a notable risk of Cross-Site Scripting (XSS) vulnerabilities. While the attack surface is minimal, with only one shortcode and no AJAX handlers or REST API routes to analyze, any unescaped output could still be exploited. The complete absence of nonce and capability checks, even on the single shortcode, further exacerbates this risk, as it suggests a lack of robust authorization and validation for the plugin's functionality.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
Checklist in Post Security Vulnerabilities
Checklist in Post Code Analysis
Output Escaping
Checklist in Post Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Checklist in Post Maintenance & Trust
Maintenance Signals
Community Trust
Checklist in Post Alternatives
amoForms
amoforms
Create forms and manage submissions easily with a simple interface. Contact forms, subscription forms, or other forms for WordPress. Absolutely FREE!
Login Form Anywhere
login-form-anywhere
Allow admin to show login from anywhere in Wordpress.
Wpautop Mask
wpautop-mask
Toggle wpautop with shortcodes.
PrePublish Checks by Kgaurav
prepublish-checks-by-kgaurav
A plugin that checks to ensure variety of conditions are being met before any new post can be published.Eg-Minimum Title length,Featured Image,etc.
Advanced Excerpt
advanced-excerpt
Control the appearance of WordPress post excerpts
Checklist in Post Developer Profile
1 plugin · 400 total installs
How We Detect Checklist in Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/checklist-in-post/css/checklist_in_post_frontend.css/wp-content/plugins/checklist-in-post/checklist_in_post_frontend.js/wp-content/plugins/checklist-in-post/checklist_in_post.js/wp-content/plugins/checklist-in-post/css/checklist_in_post.csshttps://maxcdn.bootstrapcdn.com/font-awesome/4.4.0/css/font-awesome.min.cssHTML / DOM Fingerprints
checklist_in_postoptions<div class='checklist_in_post'>