
Custom Page Templates Setup Security & Risk Analysis
wordpress.org/plugins/custom-page-templates-setupEasily add custom page templates without having to use ftp or keep track of changing themes.
Is Custom Page Templates Setup Safe to Use in 2026?
Generally Safe
Score 85/100Custom Page Templates Setup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the 'custom-page-templates-setup' v1.1 plugin appears to be a mixed bag, showing some good practices but also significant areas of concern. On the positive side, the plugin exhibits zero known CVEs, zero critical or high severity vulnerabilities in its history, and all SQL queries are properly prepared, which are strong indicators of a well-maintained and secure codebase. The absence of external HTTP requests, shortcodes, cron events, and REST API routes without permission callbacks also contributes to a reduced attack surface.
However, the static analysis reveals several critical weaknesses. Notably, 100% of the seven detected output operations are not properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete absence of nonce checks and capability checks on any of its entry points, coupled with a file operation that lacks clear context on its security implications, raises serious questions about authentication and authorization. The total lack of taint analysis flows and the absence of dangerous function usage might be due to the limited scope of analysis or the plugin's functionality, but the unescaped output and missing checks remain significant threats.
In conclusion, while the plugin's vulnerability history is clean and it adheres to good practices regarding SQL queries and SQLi prevention, the unescaped output and lack of authentication/authorization checks represent immediate and severe risks. These vulnerabilities could allow for arbitrary code execution or data manipulation if an attacker can trigger these unescaped outputs or bypass authorization. The plugin is likely safe from known external threats, but internal threats or sophisticated attackers could exploit the identified weaknesses.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
- Unclear security of file operation
Custom Page Templates Setup Security Vulnerabilities
Custom Page Templates Setup Code Analysis
Output Escaping
Custom Page Templates Setup Attack Surface
WordPress Hooks 6
Maintenance & Trust
Custom Page Templates Setup Maintenance & Trust
Maintenance Signals
Community Trust
Custom Page Templates Setup Alternatives
Display custom fields in the frontend – Post and User Profile Fields
shortcode-to-display-post-and-user-data
Display post and user custom fields data anywhere on the frontend using a shortcode, including advanced custom fields (ACF) fields.
WP Page Templates
custom-page-templates-by-vegacorp
Create full width pages, add left or right sidebars, add above or below content sidebars.
Hide Header on Posts for Landing Pages
hide-header-on-posts-for-a-landing-page
Hide header on single post pages.
Custom HTML/PHP Post Templates
html-php-pages-and-posts
Use your HTML or PHP files for any page or post.
Posts Page: Use Page Template
posts-page-custom-template
When setting the 'Posts Page:' to a custom page within the 'Reading' settings of Wordpress, it will by default, ignore that page&# …
Custom Page Templates Setup Developer Profile
1 plugin · 10 total installs
How We Detect Custom Page Templates Setup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-page-templates-setup/cpt_options.css/wp-content/plugins/custom-page-templates-setup/cpt_options.js/wp-content/plugins/custom-page-templates-setup/cpt_options.jscustom-page-templates-setup/cpt_options.css?ver=custom-page-templates-setup/cpt_options.js?ver=HTML / DOM Fingerprints
<!-- Plugin Name: Custom Page Templates Setup --><!-- Plugin URI: http://spencerbrown.website/custom-page-templates-setup-plugin --><!-- Description: Easily add custom page templates without having to use ftp or keep track of changing themes. --><!-- Author: Spencer Brown -->+29 more