
Nested Posts by CurateWP Security & Risk Analysis
wordpress.org/plugins/curatewp-nested-postsDisplay a list of posts which includes descendants of the current page.
Is Nested Posts by CurateWP Safe to Use in 2026?
Generally Safe
Score 85/100Nested Posts by CurateWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "curatewp-nested-posts" plugin v1.1.0 exhibits a generally strong security posture based on the provided static analysis. The complete absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% output escaping indicate robust development practices. The lack of file operations and external HTTP requests further reduces the attack surface. However, the analysis does highlight a significant concern: a complete lack of nonce checks and capability checks. This means that while the identified entry points (shortcodes) are not directly vulnerable to SQL injection or XSS through code logic, there are no built-in protections against unauthorized execution or privilege escalation if an attacker can trigger these shortcodes. The vulnerability history is clean, with no recorded CVEs, which is a positive sign. The taint analysis showing unsanitized paths is concerning, although no critical or high severity issues were found directly linked to them. The absence of historical vulnerabilities coupled with the lack of specific checks suggests a potential oversight rather than malicious intent. In conclusion, the plugin is well-written in terms of data handling and output sanitization, but the lack of authentication and authorization checks on its entry points represents a notable security weakness that should be addressed.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Flows with unsanitized paths (though not critical/high)
Nested Posts by CurateWP Security Vulnerabilities
Nested Posts by CurateWP Code Analysis
Output Escaping
Data Flow Analysis
Nested Posts by CurateWP Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Nested Posts by CurateWP Maintenance & Trust
Maintenance Signals
Community Trust
Nested Posts by CurateWP Alternatives
Related Posts by CurateWP
curatewp-related-posts
Keep visitors engaged on your blog by highlighting relevant content of each published post.
Nested Blog Posts
nested-blog-posts
Enable parent/child hierarchy for standard Posts and generate nested permalinks like /parent/child/ (unlimited depth).
Breadcrumb NavXT
breadcrumb-navxt
Adds breadcrumb navigation showing the visitor's path to their current location.
WP-PageNavi
wp-pagenavi
Adds a more advanced paging navigation interface.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
Nested Posts by CurateWP Developer Profile
6 plugins · 160 total installs
How We Detect Nested Posts by CurateWP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/curatewp-nested-posts/build/layouts.css/wp-content/plugins/curatewp-nested-posts/build/index.js/wp-content/plugins/curatewp-nested-posts/build/index.jscuratewp-nested-posts/build/layouts.css?ver=curatewp-nested-posts/build/index.js?ver=HTML / DOM Fingerprints
curatewp-nested-postscuratewp/nested-posts<div class="curatewp-nested-posts"<div class="cwpnp-wrap">