
Curated Query Loop Security & Risk Analysis
wordpress.org/plugins/curated-query-loopSelect specific posts to use in a Query Loop
Is Curated Query Loop Safe to Use in 2026?
Generally Safe
Score 100/100Curated Query Loop has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'curated-query-loop' plugin version 0.2.1 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and complete output escaping suggest good coding practices to prevent common vulnerabilities. Furthermore, the plugin has no recorded history of vulnerabilities, which is a positive indicator. The static analysis also reports zero attack surface entry points and zero taint analysis flows, further reinforcing its apparent security.
Despite these strengths, the complete lack of nonce checks and capability checks across all entry points is a significant concern. While the current analysis shows no exposed entry points, any future additions or modifications to the plugin that introduce AJAX handlers, REST API routes, or shortcodes without proper authentication and authorization mechanisms would immediately present a high risk. The plugin's current codebase appears secure due to its limited functionality and lack of exposed interfaces, but this security is conditional on its static nature and does not demonstrate robust defense-in-depth.
In conclusion, 'curated-query-loop' v0.2.1 currently presents a low risk due to its clean code and lack of vulnerability history. However, the absence of authentication and authorization checks in its foundational design represents a critical potential weakness that requires careful consideration for future development. The plugin's security is currently dependent on its limited attack surface rather than proactive security measures.
Key Concerns
- No nonce checks detected
- No capability checks detected
Curated Query Loop Security Vulnerabilities
Curated Query Loop Release Timeline
Curated Query Loop Code Analysis
Output Escaping
Curated Query Loop Attack Surface
WordPress Hooks 8
Maintenance & Trust
Curated Query Loop Maintenance & Trust
Maintenance Signals
Community Trust
Curated Query Loop Alternatives
Query Loop Load More
query-loop-load-more
This WordPress plugin adds a load more option to the Query Loop Pagination block in Gutenberg, allowing users to load more posts without refreshing th …
Query Loop Post Selector
query-loop-post-selector
A native query loop extension that adds a new option in the filter that allows user to specifically pick certain posts to display
Query Loop Exclude Posts
query-loop-exclude-posts
Extends the Query Loop Block to allow excluding specific posts.
Solarplexus
solarplexus
Solarplexus gives developers a powerful tool for adding dynamic display blocks.
Cherry Pick for Query Loop
cherry-pick-for-query-loop
Pick specific posts for Query Loop block and display them in your preferred order.
Curated Query Loop Developer Profile
1 plugin · 10 total installs
How We Detect Curated Query Loop
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/curated-query-loop/dist/css/admin.css/wp-content/plugins/curated-query-loop/dist/js/admin.js/wp-content/plugins/curated-query-loop/dist/js/admin.jscurated-query-loop/dist/css/admin.css?ver=curated-query-loop/dist/js/admin.js?ver=