
Custom Post Display Security & Risk Analysis
wordpress.org/plugins/custom-post-displayThe Custom Post Display Plugin lets you add a widget that displays the content of your desired custom post type.
Is Custom Post Display Safe to Use in 2026?
Generally Safe
Score 85/100Custom Post Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-post-display" v1.2 plugin exhibits a mixed security posture. On the positive side, the plugin has no known vulnerabilities (CVEs), a clean vulnerability history, and does not perform file operations or external HTTP requests. Furthermore, all identified SQL queries utilize prepared statements, which is a strong security practice. However, there are significant concerns regarding code quality and potential for security issues. The presence of the `create_function` dangerous function, even if not directly exploited in static analysis, is a red flag as it can be misused. More critically, only 5% of output escaping is properly implemented, meaning 95% of the 44 output operations are potentially vulnerable to cross-site scripting (XSS) attacks. The complete absence of nonce checks and capability checks across all entry points (even though the attack surface is currently reported as zero) leaves the plugin highly exposed should any new entry points be introduced or discovered, as there will be no built-in protection against common web attacks.
Key Concerns
- Low percentage of output properly escaped
- Presence of dangerous function create_function
- No nonce checks
- No capability checks
Custom Post Display Security Vulnerabilities
Custom Post Display Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Custom Post Display Attack Surface
WordPress Hooks 1
Maintenance & Trust
Custom Post Display Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Display Alternatives
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
Custom Post Display Developer Profile
2 plugins · 60 total installs
How We Detect Custom Post Display
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-display/custom-post-display.phpHTML / DOM Fingerprints
alignleftalignrightwidget_id