
Custom Post Types Bubbles Security & Risk Analysis
wordpress.org/plugins/custom-post-types-bubblesEasily add notifications bubble with counters in Post Types to display either pending or draft posts.
Is Custom Post Types Bubbles Safe to Use in 2026?
Generally Safe
Score 85/100Custom Post Types Bubbles has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-post-types-bubbles" v2.0 plugin exhibits a mixed security posture. On the positive side, it has no known vulnerabilities in its history and boasts a minimal attack surface with all entry points appearing to be protected by authorization checks. The use of prepared statements for all SQL queries is also a strong indicator of good security practices in database interactions.
However, significant concerns arise from the static analysis. The presence of the `unserialize` function, particularly without clear sanitization or input validation context provided in the data, is a notable risk. Furthermore, the complete lack of output escaping across all identified output points is a critical vulnerability that could lead to cross-site scripting (XSS) attacks if user-supplied data is ever rendered without proper sanitization. The absence of capability checks on its single AJAX handler, despite a nonce check, leaves a potential gap for privilege escalation or unauthorized actions if the nonce can be bypassed or reused.
Given the absence of historical vulnerabilities, it's difficult to draw conclusions about long-term security trends. However, the current code analysis reveals a critical weakness in output handling and a potentially exploitable use of `unserialize`. While the protected attack surface is commendable, the identified code signals represent immediate and serious risks that must be addressed.
Key Concerns
- Unescaped output found in all instances
- Dangerous function 'unserialize' present
- AJAX handler without capability check
Custom Post Types Bubbles Security Vulnerabilities
Custom Post Types Bubbles Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Custom Post Types Bubbles Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Custom Post Types Bubbles Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Types Bubbles Alternatives
WP-Speech-Balloon
wp-speech-balloon
WordPress の記事内で簡単に吹き出し会話を使えるプラグインです。AMPページでも通常ページと同じように吹き出し会話を使えます。 This is a plugin that makes it easy to use balloon conversation with WordPress.
Conversation Viewer – Display Chat Bubbles
conversation-viewer-display-chat-bubbles
A plugin for displaying chat bubbles on your site, like in their original messaging apps.
AudioTyped UX – Chat-Style Transcripts for Podcasts
audiotyped-ux
Chat-style transcript layouts with speaker bubbles for readable, SEO-friendly interviews on podcast & interview websites.
Bubbles Animates Name
bubbles-name
Animates your name. When you move your mouse over your name, bubbles will scatter away and then reassemble.
MAS Static Content
mas-static-content
MAS Static Content is a free plugin that allows you to to create a custom post type static content and use it with shortcode.
Custom Post Types Bubbles Developer Profile
2 plugins · 450 total installs
How We Detect Custom Post Types Bubbles
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-types-bubbles/assets/css/cptb.min.css/wp-content/plugins/custom-post-types-bubbles/assets/js/cptb.min.js/wp-content/plugins/custom-post-types-bubbles/assets/js/cptb.min.jsHTML / DOM Fingerprints
cpt-itemis-activejs-toggle-cpttoggle-cptpost-status-list-wrapperpost-status-listpost-status-itemjs-toggle-status+8 moredata-cptdata-post-statusdata-colorcptb-noncenonce