Custom Category Listing Page Security & Risk Analysis

wordpress.org/plugins/custom-category-listing-page

Custom Category Listing Page Allow to List Category Posts for each Category by Order ex: [post_listing]

40 active installs v2.0.5 PHP 5.6+ WP 3.3+ Updated Nov 14, 2019
categoriescmslistposts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Category Listing Page Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Category Listing Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "custom-category-listing-page" plugin v2.0.5 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin has no recorded CVEs, indicating a history of responsible development or a lack of prior discovery of vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. The presence of nonce and capability checks on all identified entry points is a positive sign for preventing common WordPress attacks.

However, a significant concern arises from the low percentage of properly escaped output (29%). This indicates that user-supplied or dynamic data is likely being rendered directly into the HTML without sufficient sanitization, creating a risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis shows no reported unsanitized flows, the low output escaping rate suggests that such vulnerabilities could exist and may not have been detected by the analysis methods used. The limited attack surface (1 shortcode) is a positive factor, but the unescaped output remains a notable weakness that requires attention.

In conclusion, the plugin demonstrates good security practices regarding authentication and data handling for SQL queries. The vulnerability history is clean, which is reassuring. The primary weakness lies in the inadequate output escaping, posing a potential XSS risk. Addressing this output escaping issue should be the priority to fully mitigate potential security threats.

Key Concerns

  • Low output escaping rate
Vulnerabilities
None known

Custom Category Listing Page Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Custom Category Listing Page Release Timeline

v2.0.5Current
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Custom Category Listing Page Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
10 escaped
Nonce Checks
5
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped35 total outputs
Attack Surface

Custom Category Listing Page Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[post_listing] custom-category-listing-page.php:25
WordPress Hooks 12
actionwp_enqueue_scriptscustom-category-listing-page.php:13
actionadmin_enqueue_scriptscustom-category-listing-page.php:14
actionadd_meta_boxescustom-category-listing-page.php:15
actionsave_postcustom-category-listing-page.php:16
actionadd_meta_boxescustom-category-listing-page.php:17
actionsave_postcustom-category-listing-page.php:18
actionadd_meta_boxescustom-category-listing-page.php:19
actionsave_postcustom-category-listing-page.php:20
actionadd_meta_boxescustom-category-listing-page.php:21
actionsave_postcustom-category-listing-page.php:22
actionadd_meta_boxescustom-category-listing-page.php:23
actionsave_postcustom-category-listing-page.php:24
Maintenance & Trust

Custom Category Listing Page Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedNov 14, 2019
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Custom Category Listing Page Developer Profile

TRooInbound

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Category Listing Page

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Custom Category Listing Page