
Custom Post Type List Shortcode Security & Risk Analysis
wordpress.org/plugins/custom-post-type-list-shortcodeA shortcode with which you can easily list all of the posts within a post-type and sort by regular or custom fields.
Is Custom Post Type List Shortcode Safe to Use in 2026?
Use With Caution
Score 64/100Custom Post Type List Shortcode has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The static analysis for the "custom-post-type-list-shortcode" plugin v1.4.4 indicates a generally robust security posture with no identified dangerous functions, unsanitized taint flows, or direct SQL injection risks due to prepared statements. All identified outputs are also properly escaped, and the plugin does not perform file operations or external HTTP requests. The lack of detected AJAX handlers, REST API routes, shortcodes, or cron events without authentication or permission checks contributes to a minimal attack surface, which is a positive sign.
However, the plugin has a known medium severity vulnerability for Cross-Site Scripting (XSS) that remains unpatched. This historical vulnerability, coupled with the complete absence of nonce and capability checks in the static analysis, raises concerns. While the current version might not exhibit these issues in the analyzed code paths, the lack of these fundamental security checks suggests a potential for vulnerabilities to arise in future development or if the plugin's functionality were to expand. The absence of these checks can be a systemic weakness, even if not immediately exploitable in the current static scan.
In conclusion, while the plugin demonstrates good practices in areas like SQL handling and output escaping, the unpatched XSS vulnerability and the complete lack of nonces and capability checks represent significant security weaknesses. Users should be aware of the past vulnerability and the potential for future issues due to the absence of essential security mechanisms.
Key Concerns
- Unpatched CVEs
- Missing nonce checks
- Missing capability checks
Custom Post Type List Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Custom Post Type List Shortcode <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Custom Post Type List Shortcode Code Analysis
Custom Post Type List Shortcode Attack Surface
WordPress Hooks 1
Maintenance & Trust
Custom Post Type List Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Type List Shortcode Alternatives
W4 Post List
w4-post-list
W4 Post List lets you create a list of posts, terms, users or a combined one. Decorate output using shortcodes. It's just easy and fun.
News CPT
news-cpt
A quick, easy way to add an extensible News custom post type to Wordpress.
SuperLight CPT Manager
superlight-cpt-manager
Create and manage custom post types instantly. Each CPT gets its own shortcode.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Post Types Unlimited
post-types-unlimited
Create unlimited custom post types and custom taxonomies.
Custom Post Type List Shortcode Developer Profile
1 plugin · 100 total installs
How We Detect Custom Post Type List Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-type-list-shortcode/css/style.css/wp-content/plugins/custom-post-type-list-shortcode/js/admin.js/wp-content/plugins/custom-post-type-list-shortcode/js/frontend.js/wp-content/plugins/custom-post-type-list-shortcode/js/admin.js/wp-content/plugins/custom-post-type-list-shortcode/js/frontend.jscustom-post-type-list-shortcode/css/style.css?ver=custom-post-type-list-shortcode/js/admin.js?ver=custom-post-type-list-shortcode/js/frontend.js?ver=