
Custom Post Type Maker Security & Risk Analysis
wordpress.org/plugins/custom-post-type-makerCustom Post Type Maker lets you create Custom Post Types and custom Taxonomies in a user friendly way.
Is Custom Post Type Maker Safe to Use in 2026?
Generally Safe
Score 85/100Custom Post Type Maker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-post-type-maker" plugin v1.2.0 presents a mixed security posture. On the positive side, it exhibits strong adherence to secure coding practices regarding SQL queries, consistently utilizing prepared statements. The absence of known CVEs and a clean vulnerability history also suggest a generally stable and well-maintained codebase. However, significant concerns arise from the presence of dangerous functions, specifically "unserialize," which can be a vector for serious security issues if not handled with extreme care and proper input validation. Furthermore, the low percentage of properly escaped outputs indicates a potential for cross-site scripting (XSS) vulnerabilities, as user-supplied data might be rendered directly in the browser without adequate sanitization. The plugin's attack surface appears minimal with no publicly exposed AJAX, REST API, or shortcode entry points, and a single nonce check is present, but the lack of capability checks on this entry point is a notable weakness. While the taint analysis shows no reported issues, this may be due to the limited scope of the analysis or the plugin's specific functionalities, and the "unserialize" function remains a potent risk if exploited. In conclusion, while the plugin demonstrates good practices in areas like SQL security and boasts a clean vulnerability record, the potential for XSS due to insufficient output escaping and the inherent risks associated with "unserialize" warrant caution.
Key Concerns
- Dangerous function: unserialize usage
- Output escaping is not fully proper (67%)
- No capability checks on entry points
Custom Post Type Maker Security Vulnerabilities
Custom Post Type Maker Code Analysis
Dangerous Functions Found
Output Escaping
Custom Post Type Maker Attack Surface
WordPress Hooks 16
Maintenance & Trust
Custom Post Type Maker Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Type Maker Alternatives
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
Sydney Toolbox
sydney-toolbox
Registers custom post types and custom fields for the Sydney theme
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Custom Post Type Maker Developer Profile
2 plugins · 9K total installs
How We Detect Custom Post Type Maker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-type-maker/css/overview.css/wp-content/plugins/custom-post-type-maker/js/overview.js/wp-content/plugins/custom-post-type-maker/css/add-edit.css/wp-content/plugins/custom-post-type-maker/js/add-edit.jscustom-post-type-maker/js/overview.js?ver=0.0.1custom-post-type-maker/css/overview.css?ver=custom-post-type-maker/js/add-edit.js?ver=custom-post-type-maker/css/add-edit.css?ver=HTML / DOM Fingerprints
cptm-wrapcptm-add-edit-wrapcptm-post-type-optionscptm-taxonomy-optionsdata-cptm-post-typedata-cptm-taxonomycptm_var