
DeMomentSomTres Display Posts Shortcode Security & Risk Analysis
wordpress.org/plugins/demomentsomtres-display-posts-shortcodeDisplay a listing of posts using the [display-posts] shortcode allowing multiple network instances.
Is DeMomentSomTres Display Posts Shortcode Safe to Use in 2026?
Generally Safe
Score 100/100DeMomentSomTres Display Posts Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "demomentsomtres-display-posts-shortcode" v2.5 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers and REST API routes with missing authentication checks, coupled with no identified dangerous functions or file operations, indicates a well-contained codebase. Furthermore, all SQL queries are prepared, and there are no external HTTP requests or bundled libraries, reducing common attack vectors. The vulnerability history is also clean, with no known CVEs, suggesting a history of secure development or diligent patching.
However, there are areas for improvement. The presence of a shortcode without any listed capability checks or nonce checks represents a potential, albeit small, attack surface. While taint analysis did not reveal any immediate high-severity issues, the lack of detailed taint flow analysis is a limitation. The output escaping, while mostly proper, has a small percentage that is not, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped content is user-controlled or sensitive. Overall, the plugin is relatively secure, but the shortcode's access control and the minor unescaped output warrant attention for enhanced security.
Key Concerns
- Shortcode without capability checks
- Percentage of output not properly escaped
DeMomentSomTres Display Posts Shortcode Security Vulnerabilities
DeMomentSomTres Display Posts Shortcode Code Analysis
Output Escaping
DeMomentSomTres Display Posts Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
DeMomentSomTres Display Posts Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
DeMomentSomTres Display Posts Shortcode Alternatives
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
LH Display Posts Shortcode
lh-display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by author, post type and more.
Load Posts in React
load-posts-in-react
A simple shortcode plugin to fetch and display WordPress posts dynamically using React.
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
Page Specific Scripts
page-specific-scripts
Simple and easy to use wordpress plugin to add jQuery/JS Scripts only to specific pages.
DeMomentSomTres Display Posts Shortcode Developer Profile
15 plugins · 340 total installs
How We Detect DeMomentSomTres Display Posts Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/demomentsomtres-display-posts-shortcode/css/style.css/wp-content/plugins/demomentsomtres-display-posts-shortcode/js/demomentsomtres_display_posts_shortcode.js/wp-content/plugins/demomentsomtres-display-posts-shortcode/js/demomentsomtres_display_posts_shortcode.jsdemomentsomtres-display-posts-shortcode/css/style.css?ver=demomentsomtres-display-posts-shortcode/js/demomentsomtres_display_posts_shortcode.js?ver=HTML / DOM Fingerprints
demomentsomtres-display-posts-shortcode<!-- DeMomentSomTres Display Posts Shortcode -->data-dms3-dps-jsoutputdata-dms3-dps-jsfunctiondata-dms3-dps-jsparamsdata-dms3-dps-empty-messagedms3DPSDeMomentSomTresDisplayPostShortcode<div class="demomentsomtres-display-posts-shortcode"><ul class="display-posts"><li class="display-posts-item">