Custom-Single Security & Risk Analysis

wordpress.org/plugins/custom-single

Enables themes to support custom single.php templates per category in the form single-CATEGORYID.php.

10 active installs v1.0.0 PHP + WP 3.5+ Updated Dec 11, 2013
categoriescustomcustom-templatespoststemplate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom-Single Safe to Use in 2026?

Generally Safe

Score 85/100

Custom-Single has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "custom-single" plugin version 1.0.0 demonstrates an exceptionally strong security posture based on the provided static analysis. The absence of any identified attack surface points, dangerous functions, unescaped output, raw SQL queries, or external HTTP requests is highly commendable. Furthermore, the plugin's taint analysis reveals no unsanitized data flows, indicating a thorough approach to preventing common web vulnerabilities. The vulnerability history also shows a clean slate, with no past or present CVEs, suggesting a history of secure development and maintenance.

While the lack of apparent vulnerabilities is a significant strength, it's important to note that the analysis might be limited by the scope of static analysis tools. The reported zero entry points and zero capability checks, while appearing secure on the surface, could also imply a plugin with very limited functionality that doesn't require user interaction or specific permissions. This means the plugin might not be performing complex operations that would typically introduce security risks.

In conclusion, "custom-single" v1.0.0 appears to be a very secure plugin. Its code adheres to best practices by avoiding dangerous functions, sanitizing inputs, and properly escaping outputs. The lack of historical vulnerabilities further reinforces this positive assessment. However, future assessments should consider the actual functionality and scope of the plugin to ensure that its limited attack surface is not a result of missing features rather than comprehensive security implementation.

Vulnerabilities
None known

Custom-Single Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Custom-Single Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Custom-Single Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitcustom-single.php:15
actionwp_logoutcustom-single.php:16
actionwp_logincustom-single.php:17
filtersingle_templatecustom-single.php:93
Maintenance & Trust

Custom-Single Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedDec 11, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Custom-Single Developer Profile

Tor N. Johnson

5 plugins · 1K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom-Single

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Custom-Single