
Custom Posts Per Page Security & Risk Analysis
wordpress.org/plugins/custom-posts-per-pageCustom Posts Per Page provides a settings page in your WordPress admin that allows you to specify how many posts are displayed for different views.
Is Custom Posts Per Page Safe to Use in 2026?
Generally Safe
Score 85/100Custom Posts Per Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'custom-posts-per-page' plugin version 1.7.1 exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL injection vulnerabilities due to the use of prepared statements, or file operations. The output escaping is also very high, with 96% of outputs properly escaped. Furthermore, the plugin has no recorded vulnerabilities or CVEs, indicating a history of stable and secure development. The attack surface is effectively zero, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication or permission checks. This suggests diligent security practices by the developers.
However, a notable concern arises from the complete absence of nonce checks and capability checks. While the current analysis shows no direct vulnerabilities stemming from this, it represents a significant gap in WordPress security best practices. In the absence of these checks, if any new entry points were introduced or existing ones were overlooked during development, it could lead to potential unauthorized actions or privilege escalation. The taint analysis also shows zero flows, which is positive but could also be a reflection of the limited attack surface and potential for unanalyzed flows if the code were more complex.
In conclusion, the plugin is currently very secure, with no known vulnerabilities and a well-mitigated attack surface. The developers have clearly prioritized secure coding practices. The primary weakness lies in the lack of nonce and capability checks, which, while not currently exploited, introduces a theoretical risk that could be addressed by implementing these standard WordPress security measures.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
Custom Posts Per Page Security Vulnerabilities
Custom Posts Per Page Code Analysis
Output Escaping
Custom Posts Per Page Attack Surface
WordPress Hooks 7
Maintenance & Trust
Custom Posts Per Page Maintenance & Trust
Maintenance Signals
Community Trust
Custom Posts Per Page Alternatives
Custom Posts Per Page Reloaded
custom-posts-per-page-reloaded
Custom Posts Per Page Reloaded provides a settings page in your WordPress admin that allows you to specify how many posts are displayed for different …
Change Administration Email
change-administration-email
Change the Site's Administration Email Address on the General Settings page without the confirmation email.
Timetable
plan-lekcji
A WordPress plugin for managing school timetables based on files generated by Vulcan Optivum, allowing ZIP file uploads.
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
Adminimize
adminimize
Adminimize that lets you hide 'unnecessary' items from the WordPress backend
Custom Posts Per Page Developer Profile
5 plugins · 1K total installs
How We Detect Custom Posts Per Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-posts-per-page/css/settings.css/wp-content/plugins/custom-posts-per-page/js/settings.js/wp-content/plugins/custom-posts-per-page/js/settings.jscustom-posts-per-page/css/settings.css?ver=custom-posts-per-page/js/settings.js?ver=