
Create Posts & Terms Security & Risk Analysis
wordpress.org/plugins/create-posts-termsCreate pages, posts, custom post items, categories, post tags & custom taxonomies terms in bulk.
Is Create Posts & Terms Safe to Use in 2026?
Use With Caution
Score 63/100Create Posts & Terms has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "create-posts-terms" v1.3.1 plugin exhibits a mixed security posture. On the positive side, the static analysis indicates no dangerous functions, raw SQL queries, file operations, external HTTP requests, or obvious entry points like AJAX handlers, REST API routes, shortcodes, or cron events lacking authentication or permission checks. The SQL queries that are present use prepared statements, which is a strong security practice.
However, a significant concern arises from the output escaping. With 8 total outputs and 0% properly escaped, this suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from the plugin, or is influenced by user input, could be susceptible to injection. Furthermore, the vulnerability history reveals a previously patched medium-severity CSRF vulnerability and a currently unpatched medium-severity vulnerability. The recurrence of CSRF issues in the past, coupled with the unpatched vulnerability, indicates a need for more robust security development practices.
In conclusion, while the plugin has successfully minimized its direct attack surface and employs secure database practices, the lack of output escaping and the presence of unpatched vulnerabilities represent significant weaknesses. The development team should prioritize addressing the output escaping and investigating the currently unpatched vulnerability to mitigate potential risks to user data and site integrity.
Key Concerns
- Unescaped output
- Unpatched CVE
- Capability checks present, but lack of other security controls
Create Posts & Terms Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Create Posts & Terms <= 1.3.1 - Cross-Site Request Forgery
Create Posts & Terms Release Timeline
Create Posts & Terms Code Analysis
Output Escaping
Data Flow Analysis
Create Posts & Terms Attack Surface
WordPress Hooks 1
Maintenance & Trust
Create Posts & Terms Maintenance & Trust
Maintenance Signals
Community Trust
Create Posts & Terms Alternatives
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
SEO Auto Linker
wpa-seo-auto-linker
SEO Auto Linker assists in creating cornerstone SEO content. This is not a full replacement for SEO plugins.
Bainternet Posts Creation Limits
bainternet-posts-creation-limits
this plugin helps you to limit the number of posts/pages/custom post types each user can create on your site.
WP Multilingual Sitemap
wp-multilingual-sitemap
Allows creating complete multilingual sitemaps of your entire blog.
Locus
locus
Locus allows you display any post, page or post type in widgetized areas of you site.
Create Posts & Terms Developer Profile
1 plugin · 70 total installs
How We Detect Create Posts & Terms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/create-posts-terms/css/style.css/wp-content/plugins/create-posts-terms/js/main.jscreate-posts-terms/css/style.css?ver=create-posts-terms/js/main.js?ver=HTML / DOM Fingerprints
wrapdata-post-typecp_create_post_terms