
CUSTOM OPTIONS PLUS POST IN Security & Risk Analysis
wordpress.org/plugins/custom-options-plus-post-inThis plugin is create to custom options in your WordPress. You can use in the Template and Shortcode.
Is CUSTOM OPTIONS PLUS POST IN Safe to Use in 2026?
Generally Safe
Score 85/100CUSTOM OPTIONS PLUS POST IN has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'custom-options-plus-post-in' v1.4.1 plugin demonstrates a generally strong security posture, characterized by the exclusive use of prepared statements for all SQL queries and a robust presence of nonce and capability checks. This indicates a good understanding of fundamental WordPress security practices, particularly in preventing common SQL injection and authorization bypass vulnerabilities.
However, a significant concern arises from the 'Output escaping' metric, with only 17% of outputs being properly escaped. This leaves a considerable portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks, where unsanitized data could be injected into the page and executed in a user's browser. Additionally, the taint analysis revealed one flow with an unsanitized path, which, while not flagged as critical or high severity in this specific report, warrants investigation as it could represent a potential avenue for file inclusion or path traversal vulnerabilities if exploited in conjunction with other weaknesses.
The complete absence of known vulnerabilities in its history is a positive indicator, suggesting a history of stable and relatively secure development. Nonetheless, the identified output escaping deficiency and the unsanitized path flow represent exploitable weaknesses that could be leveraged by attackers. While the overall security is good due to strong SQL and authentication practices, the XSS risk and the unsanitized path need to be addressed to achieve a truly secure state.
Key Concerns
- Low percentage of properly escaped output
- Flow with unsanitized path found
CUSTOM OPTIONS PLUS POST IN Security Vulnerabilities
CUSTOM OPTIONS PLUS POST IN Release Timeline
CUSTOM OPTIONS PLUS POST IN Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
CUSTOM OPTIONS PLUS POST IN Attack Surface
WordPress Hooks 13
Maintenance & Trust
CUSTOM OPTIONS PLUS POST IN Maintenance & Trust
Maintenance Signals
Community Trust
CUSTOM OPTIONS PLUS POST IN Alternatives
Abandon Themes Admin
abandon-theme-options
This is a WordPress plugin that adds an admin options page to your theme and all the main options a theme designer would need.
WP Admin UI Customize
wp-admin-ui-customize
Customize the management screen UI.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Content Blocks (Custom Post Widget)
custom-post-widget
This plugin enables you to edit and display Content Blocks in a sidebar widget or using a shortcode.
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
CUSTOM OPTIONS PLUS POST IN Developer Profile
12 plugins · 47K total installs
How We Detect CUSTOM OPTIONS PLUS POST IN
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-options-plus-post-in/manager/assets/css/manager.css/wp-content/plugins/custom-options-plus-post-in/manager/assets/js/manager.js/wp-content/plugins/custom-options-plus-post-in/manager/assets/js/manager.jscustom-options-plus-post-in/manager/assets/js/manager.js?ver=custom-options-plus-post-in/manager/assets/css/manager.css?ver=HTML / DOM Fingerprints
coppiclass="wrap coppi"coppi