
CPO Content Types Security & Risk Analysis
wordpress.org/plugins/cpo-content-typesAdd support for special content types in your website, such as a portfolio, features, and slides.
Is CPO Content Types Safe to Use in 2026?
Generally Safe
Score 100/100CPO Content Types has a strong security track record. Known vulnerabilities have been patched promptly.
The "cpo-content-types" plugin version 1.1.1 exhibits a generally good security posture with some notable weaknesses. The plugin has a very small attack surface, with only one AJAX handler, and importantly, this handler appears to be protected by authentication checks, which is a positive sign. The code analysis shows a healthy use of prepared statements for SQL queries (91%) and proper output escaping for the majority of outputs (78%). The absence of file operations and external HTTP requests further strengthens its security profile. However, the plugin has a known medium severity vulnerability related to Cross-Site Scripting (XSS) discovered in March 2023, which is currently unpatched. While the static analysis didn't reveal any direct XSS vulnerabilities in the provided data, the historical vulnerability is a significant concern. The lack of capability checks and only two nonce checks in the code also present potential areas for improvement, as they could be leveraged in conjunction with other vulnerabilities if they existed.
Key Concerns
- Unpatched medium severity CVE found
- No capability checks found
- Output escaping could be improved (22% not escaped)
- SQL queries have some raw usage (9% not prepared)
CPO Content Types Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CPO Content Types <= 1.1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
CPO Content Types Code Analysis
SQL Query Safety
Output Escaping
CPO Content Types Attack Surface
AJAX Handlers 1
WordPress Hooks 37
Maintenance & Trust
CPO Content Types Maintenance & Trust
Maintenance Signals
Community Trust
CPO Content Types Alternatives
Smart Testimonials plugin
smart-testimonials
Smart testimonials plugin will allow webmaster to turn the boring looking testimonials into a fancy attractive page with several formatting options.
WPshed Theme Extras
wpshed-theme-extras
WTE add powerful features to your Theme. It is designed to work with WPshed Themes, but all featured can be used in any other theme.
IDT Testimonial
idt-testimonial
Simple plugin to Show testimonials on pages, widgets and posts.
Strong Testimonials
strong-testimonials
An easy-to-use testimonial plugin to collect and show customer feedback in WordPress
Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials
testimonial-free
A Customizable Testimonial plugin to Automate Collecting, Filtering, and Publishing Customer Reviews. Testimonial Slider, Grid & More to Grow Sales
CPO Content Types Developer Profile
29 plugins · 440K total installs
How We Detect CPO Content Types
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cpo-content-types/assets/css/admin.css/wp-content/plugins/cpo-content-types/assets/js/scporder.js/wp-content/plugins/cpo-content-types/assets/css/scporder.css/wp-content/plugins/cpo-content-types/assets/js/scporder.jscpo-content-types/assets/css/admin.css?ver=cpo-content-types/assets/js/scporder.js?ver=cpo-content-types/assets/css/scporder.css?ver=HTML / DOM Fingerprints
column-ctct-imagecolumn-ctct-portfolio-catscolumn-ctct-portfolio-tagscolumn-ctct-service-catscolumn-ctct-service-tagsdata-post-typescporder