
Custom Portfolio With Filtering Security & Risk Analysis
wordpress.org/plugins/custom-portfolio-with-filteringCustom Portfolio Type with filtering without page refresh Using Shortcode [portfolio]
Is Custom Portfolio With Filtering Safe to Use in 2026?
Generally Safe
Score 85/100Custom Portfolio With Filtering has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-portfolio-with-filtering" v1.0.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all its SQL queries and has no recorded vulnerability history, suggesting a mature and stable codebase. It also has a small attack surface with only one entry point (a shortcode) and no external HTTP requests or file operations, which generally reduces the potential for exploitation. However, a significant concern arises from the complete lack of output escaping. This means that any data displayed to users, especially if it originates from user input or external sources, is not being properly sanitized. This could lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website, potentially compromising user sessions or defacing the site. Additionally, the absence of nonce checks and capability checks on its sole entry point (the shortcode) means that unauthorized users could potentially trigger its functionality, although without further analysis of what the shortcode does, the direct impact of this is unclear. The lack of taint analysis results is also noted, though this may simply indicate that the analysis tools did not identify any issues or that the plugin's logic is too simple for complex taint flows to be relevant.
Key Concerns
- Output escaping is not implemented
- No nonce checks on entry points
- No capability checks on entry points
Custom Portfolio With Filtering Security Vulnerabilities
Custom Portfolio With Filtering Release Timeline
Custom Portfolio With Filtering Code Analysis
SQL Query Safety
Output Escaping
Custom Portfolio With Filtering Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Custom Portfolio With Filtering Maintenance & Trust
Maintenance Signals
Community Trust
Custom Portfolio With Filtering Alternatives
Myportfolios
myportfolio
This is a portfolio plugin that provides a animated filtring with popup just with a shortcode that also filters with category.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Visual Portfolio, Photo Gallery & Post Grid
visual-portfolio
Powerful WordPress gallery plugin for stunning photo, video & album galleries with advanced layouts and flexible block editing.
Portfolio Post Type
portfolio-post-type
This plugin registers a custom post type for portfolio items. It also registers separate portfolio taxonomies for tags and categories.
Premium Portfolio Features for Phlox theme
auxin-portfolio
Showcase your projects beautifully in Phlox theme
Custom Portfolio With Filtering Developer Profile
12 plugins · 1K total installs
How We Detect Custom Portfolio With Filtering
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-portfolio-with-filtering/assets/css/style.css/wp-content/plugins/custom-portfolio-with-filtering/assets/js/filterable.jsassets/js/filterable.jscustom-portfolio-with-filtering/assets/css/style.css?ver=custom-portfolio-with-filtering/assets/js/filterable.js?ver=HTML / DOM Fingerprints
portfolio-itemthumbportfolio-titletitle-link-noneid="portfolio-filter"id="portfolio-wrapper"id="portfolio-list"<ul id="portfolio-filter"><li><a href="#all" title="">All</a></li><li class="portfolio-item<div class="thumb"><a<p class="portfolio-title"><a class="title-link-none"