
Custom Post Taxonomy Security & Risk Analysis
wordpress.org/plugins/custom-post-taxonomyCustom Post Taxonomy
Is Custom Post Taxonomy Safe to Use in 2026?
Generally Safe
Score 85/100Custom Post Taxonomy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "custom-post-taxonomy" v1.0 exhibits a mixed security posture. On the positive side, it demonstrates a strong commitment to secure coding practices by utilizing prepared statements for all SQL queries and including nonce and capability checks. The absence of known CVEs and vulnerabilities in its history is also a positive indicator. However, a significant concern arises from the presence of five instances of the `unserialize` function. Without proper input validation and sanitization, `unserialize` can lead to object injection vulnerabilities, allowing attackers to potentially execute arbitrary code or manipulate application behavior.
The static analysis reveals a clean attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or authorization. Taint analysis also shows no identified flows with unsanitized paths, suggesting that known vulnerabilities of this type are not present in this version. Despite these strengths, the reliance on `unserialize` without explicit safeguards represents a potential blind spot. The low percentage of properly escaped output (33%) is also a minor concern that could lead to cross-site scripting (XSS) vulnerabilities if sensitive data is displayed directly to users.
Key Concerns
- Dangerous function 'unserialize' used 5 times
- Only 33% of output properly escaped
Custom Post Taxonomy Security Vulnerabilities
Custom Post Taxonomy Code Analysis
Dangerous Functions Found
Output Escaping
Custom Post Taxonomy Attack Surface
WordPress Hooks 3
Maintenance & Trust
Custom Post Taxonomy Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Taxonomy Alternatives
Remove CPT base
remove-cpt-base
Remove custom post type base slug from url
WP Change Custom Posts Slugs
wp-change-custom-post-slug
The plugin allows to can easily change slug of custom post types from WordPress admin panel.
Custom Post Type Slug Manager
cptsm-slug-manager
Easily edit or remove slugs for any custom post type. Customize your content URLs without coding.
Custom Permalinks for Custom Post Types
custom-permalinks-for-custom-post-types
Remove base slug of Custom Post Types and change the permalink structure of Custom Post Types.
WP Alternative Slug by 010Pixel
wp-alternative-slug-by-010pixel
Create alternative slug (url) for each page, post or custom post type which will redirect to same main page.
Custom Post Taxonomy Developer Profile
11 plugins · 240 total installs
How We Detect Custom Post Taxonomy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-taxonomy/css/admin.css/wp-content/plugins/custom-post-taxonomy/js/ricf.js/wp-content/plugins/custom-post-taxonomy/js/ricf.jscustom-post-taxonomy/css/admin.css?ver=1.0.0HTML / DOM Fingerprints
ricftx_script