Custom post mixItup Security & Risk Analysis

wordpress.org/plugins/custom-post-mixitup

Custom post mixItup show your profile or image gallery

10 active installs v1.1 PHP + WP 1.1+ Updated Feb 28, 2021
audio-galleryimage-galleryportfolioproduct-itemvideo-gallery
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom post mixItup Safe to Use in 2026?

Generally Safe

Score 85/100

Custom post mixItup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "custom-post-mixitup" v1.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and no recorded historical vulnerabilities is a significant strength, indicating a mature and potentially well-maintained plugin. The code analysis reveals no dangerous functions, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are all positive indicators. However, there are some areas for improvement.

The plugin has a single entry point via a shortcode. While the static analysis shows no unprotected entry points, the capability checks and nonce checks are explicitly listed as 0. This is a notable concern, as it suggests that any user, regardless of their role, could potentially interact with the shortcode's functionality without proper authorization or protection against cross-site request forgery (CSRF) attacks. Furthermore, 30% of output escaping is not properly handled, which could lead to cross-site scripting (XSS) vulnerabilities if the data being output is not sufficiently sanitized upstream.

In conclusion, while the plugin benefits from a clean history and good practices in critical areas like SQL and dangerous functions, the lack of capability and nonce checks, coupled with incomplete output escaping, presents specific vulnerabilities that need to be addressed. These weaknesses, if exploited, could lead to unauthorized actions or information disclosure.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
  • Insufficient output escaping (30%)
Vulnerabilities
None known

Custom post mixItup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Custom post mixItup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

70% escaped10 total outputs
Attack Surface

Custom post mixItup Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[showing_mixup] mentor\nss_cpm_all_display.php:14
WordPress Hooks 3
actionwp_enqueue_scriptsmentor\nss_cpm_addstyle.php:15
actioninitmentor\nss_cpm_custom_post.php:18
actionadmin_menumentor\nss_cpm_custom_post.php:19
Maintenance & Trust

Custom post mixItup Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedFeb 28, 2021
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Custom post mixItup Developer Profile

saiful.total

3 plugins · 80 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom post mixItup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-post-mixitup/assets/css/plugin-style.css/wp-content/plugins/custom-post-mixitup/assets/js/nss_custom.js/wp-content/plugins/custom-post-mixitup/assets/js/jquery.mixitup.js
Script Paths
/wp-content/plugins/custom-post-mixitup/assets/js/nss_custom.js/wp-content/plugins/custom-post-mixitup/assets/js/jquery.mixitup.js
Version Parameters
custom-post-mixitup/assets/css/plugin-style.css?ver=custom-post-mixitup/assets/js/nss_custom.js?ver=custom-post-mixitup/assets/js/jquery.mixitup.js?ver=

HTML / DOM Fingerprints

CSS Classes
controlsfiltercontainermixmesoHovernsstitlenssdetails
HTML Comments
copyRight by Nssthemecontrolcontainer
Data Attributes
data-filterdata-myorder
Shortcode Output
[showing_mixup]
FAQ

Frequently Asked Questions about Custom post mixItup