
Custom Post List Security & Risk Analysis
wordpress.org/plugins/custom-post-listDisplay a customizable list of custom post types with filtering options using the Custom Post List plugin.
Is Custom Post List Safe to Use in 2026?
Generally Safe
Score 92/100Custom Post List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-post-list" plugin v1.0.4 exhibits a generally positive security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history suggests good security practices have been maintained or that the plugin has not been a significant target. The code analysis reveals no dangerous functions, SQL queries use prepared statements exclusively, and there are no file operations or external HTTP requests, all of which are strong security indicators. However, a notable concern is the "Output escaping" metric, where only 70% of outputs are properly escaped. This leaves a portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if user-controlled data is not adequately sanitized before being displayed. While the attack surface is small and has no unprotected entry points, and taint analysis shows no critical or high severity issues, the unescaped output is the primary area of risk identified. The lack of nonce checks and capability checks on the identified shortcode is also a point of concern, as it could potentially lead to unintended actions if the shortcode were to be abused in conjunction with other vulnerabilities or social engineering tactics.
Key Concerns
- Unescaped output (30% unsanitized)
- Missing nonce check on shortcode
- Missing capability check on shortcode
Custom Post List Security Vulnerabilities
Custom Post List Release Timeline
Custom Post List Code Analysis
Output Escaping
Custom Post List Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Custom Post List Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post List Alternatives
W4 Post List
w4-post-list
W4 Post List lets you create a list of posts, terms, users or a combined one. Decorate output using shortcodes. It's just easy and fun.
Custom Post Type List Shortcode
custom-post-type-list-shortcode
A shortcode with which you can easily list all of the posts within a post-type and sort by regular or custom fields.
Advanced Custom Fields: W4 Post List Bridge
advanced-custom-fields-w4-post-list-bridge
This plugin provides a [post_field field="field-name"] shortcode connecting an Advanced Custom Fields field to your W4 Post List list templa …
AC Custom Loop Shortcode
ac-custom-loop-shortcode
A simple WordPress plugin that creates a shortcode to loop through posts, pages, or custom post types and display them anywhere on your site.
Custom Post Type Lister – CPT Lister
custom-post-type-lister-cpt-lister
This plugin allows you to list a custom post type in your posts / pages with one simple shortcode.
Custom Post List Developer Profile
2 plugins · 50 total installs
How We Detect Custom Post List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
content-wrapperblog-indexpost-itempost-bodyblog-featured-imgpost-list-contentpost-headinguser-meta-section+4 morePaginationdata-custom_post_list_post_typedata-custom_post_list_show_datedata-custom_post_list_show_featured_imagedata-custom_post_list_show_paginationdata-custom_post_list_display_authordata-custom_post_list_posts_per_page<div class="content-wrapper"><div class="blog-index"><div class="post-item clearfix"><div class="post-body clearfix">