
Custom Excerpts Security & Risk Analysis
wordpress.org/plugins/custom-excerptsCustom Excerpts allows you to create a custom excerpt length, choose HTML tags to allow and whether to make the link nofollow or dofollow.
Is Custom Excerpts Safe to Use in 2026?
Generally Safe
Score 85/100Custom Excerpts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-excerpts" plugin v1.0.1 demonstrates a generally good security posture regarding its attack surface and the use of prepared statements for SQL queries. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and file operations significantly reduces the potential entry points for attackers. Furthermore, the reported zero known CVEs and a clean vulnerability history suggest a stable and well-maintained codebase.
However, a significant concern arises from the output escaping analysis. With 100% of detected outputs not being properly escaped, this plugin presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any data processed or displayed by this plugin that originates from user input or external sources could be injected with malicious scripts. The lack of capability checks and nonce checks, while not directly flagged as risks due to the limited entry points, also represent a missed opportunity for robust authentication and authorization, which could become critical if new entry points were introduced in future versions.
In conclusion, while the plugin benefits from a small attack surface and secure SQL practices, the unescaped output is a critical flaw that requires immediate attention. The vulnerability history is positive, but the current static analysis findings highlight a specific and exploitable weakness.
Key Concerns
- Unescaped output detected
- No capability checks
- No nonce checks
Custom Excerpts Security Vulnerabilities
Custom Excerpts Code Analysis
Output Escaping
Custom Excerpts Attack Surface
WordPress Hooks 2
Maintenance & Trust
Custom Excerpts Maintenance & Trust
Maintenance Signals
Community Trust
Custom Excerpts Alternatives
Ultimate Sticky Posts Widget
ultimate-sticky-posts
This Widget works well to display sticky/posts or both.
Pauls Latest Posts
pauls-latest-posts
Display latest posts with excerpts and comments in a sidebar widget.
Recent Posts Ultimate
recent-posts-ultimate
RPU is the ultimate recent posts plugin, even allowing HTML to be displayed. Quick, easy and efficient!
End Content
end-content
Allows you to add content to the end of pages, posts or both.
Advanced Post Excerpt
advanced-post-excerpt
Replace the default Post Excerpt meta box with a superior editing experience.
Custom Excerpts Developer Profile
2 plugins · 60 total installs
How We Detect Custom Excerpts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapname="ce_html"name="ce_length"name="ce_moretext"name="ce_nofollow"value="Yes"value="No"+3 more