
Custom Post Type Archives Security & Risk Analysis
wordpress.org/plugins/custom-post-type-archivesEnables custom post type archives that will support both paging and feeds. All fully customizable.
Is Custom Post Type Archives Safe to Use in 2026?
Generally Safe
Score 85/100Custom Post Type Archives has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The custom-post-type-archives plugin v1.5.1 exhibits a generally positive security posture with a significant absence of known vulnerabilities and a clean taint analysis. The static analysis reveals a limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authorization checks. Furthermore, all identified SQL queries utilize prepared statements, indicating good database interaction practices.
However, a significant concern arises from the output escaping. With 16 total outputs and 0% properly escaped, this represents a critical vulnerability. Unescaped output is a common vector for Cross-Site Scripting (XSS) attacks, where malicious scripts could be injected into the website and executed in the user's browser. The lack of nonce checks and capability checks across the board, while not directly exploitable in this version due to the lack of entry points, indicates a lack of defensive depth that could become an issue if future versions introduce new entry points without these security measures.
The absence of any recorded vulnerabilities, including CVEs, is a strong positive indicator. This suggests that the plugin has historically been well-maintained and has not been a target for known exploits. Overall, while the plugin benefits from a small attack surface and secure database practices, the critical flaw in output escaping presents a substantial risk that needs immediate attention.
Key Concerns
- 0% of output properly escaped
- 0 Nonce checks
- 0 Capability checks
Custom Post Type Archives Security Vulnerabilities
Custom Post Type Archives Code Analysis
Output Escaping
Custom Post Type Archives Attack Surface
WordPress Hooks 10
Maintenance & Trust
Custom Post Type Archives Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Type Archives Alternatives
Zippy
zippy
Incredibly easy solution to archive pages and posts as zip file and unpack them back even on the other website!
Post Type Archive Descriptions
post-type-archive-descriptions
Enables an editable description to display on post type archive pages. Show the description with WordPress's the_archive_description() function t …
PTAPS – Post Type Archive Pages and Permalink Settings
post-type-archive-pages-and-permalink-settings
Use archive pages for custom post types and improve WordPress SEO by managing permalinks for custom post types and taxonomies.
Genesis Custom Post Types Archives
genesis-custom-post-types-archives
Allows you to customize Genesis Custom Post Type archive pages for solid SEO.
Custom Post Archives
custom-post-archives
Custom Post Archives creates a fully featured set of archives for each post type using a robust back-end and native templating functionality.
Custom Post Type Archives Developer Profile
1 plugin · 200 total installs
How We Detect Custom Post Type Archives
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-type-archives/css/style.css/wp-content/plugins/custom-post-type-archives/js/pta-admin.js/wp-content/plugins/custom-post-type-archives/js/pta-admin.jscustom-post-type-archives/css/style.css?ver=custom-post-type-archives/js/pta-admin.js?ver=HTML / DOM Fingerprints
pta-options-page<!-- Meta box for adding Post Type Archive Links to menus --><!-- This is the main options page for Post Type Archives --><!-- Custom post type archives -->data-pta-post-typepta_options