
Display A Post Security & Risk Analysis
wordpress.org/plugins/display-a-postThis is a super simple plugin that displays a specific post by post name (slug) or id. This plugin is very light weight and easy to use in pages, post …
Is Display A Post Safe to Use in 2026?
Generally Safe
Score 85/100Display A Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'display-a-post' plugin v1.1 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries executed via prepared statements, and properly escaped output are excellent indicators of good development practices. The fact that all identified code signals (SQL, output) are handled securely mitigates common web application vulnerabilities.
However, the analysis reveals a significant concern regarding the lack of any explicit security checks on its entry points. With one shortcode identified as the sole entry point, the absence of nonce checks and capability checks is a notable weakness. While there are no AJAX handlers or REST API routes to assess for authentication, the shortcode's functionality could potentially be exploited if it processes user-supplied data in any way without proper validation or authorization. The plugin's vulnerability history being entirely clean is a positive sign, suggesting the developers have historically prioritized security. Nevertheless, the current lack of authorization on the shortcode remains a point of potential risk.
In conclusion, while the plugin is built with sound coding practices concerning data handling and query execution, the absence of security checks on its shortcode presents a tangible risk. The clean vulnerability history is encouraging, but it doesn't negate the immediate concern of an unprotected entry point. Developers should prioritize implementing nonce and capability checks for the shortcode to ensure it can only be executed by authorized users and prevent potential misuse.
Key Concerns
- Shortcode without nonce checks
- Shortcode without capability checks
Display A Post Security Vulnerabilities
Display A Post Code Analysis
Display A Post Attack Surface
Shortcodes 1
Maintenance & Trust
Display A Post Maintenance & Trust
Maintenance Signals
Community Trust
Display A Post Alternatives
AK Featured Post Widget
akfeatured-post-widget
A widget that you can use to display your blog posts, custom post types, or woocommerce products!
Fancy Posts Widget
fancy-posts-widget
Another posts widget plugin
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Show IDs by DraftPress
wpsite-show-ids
The Show IDs plugin displays the ID of all posts, categories, pages, taxonomies, users, tags, and more.
Display Post Types – Post Grid, post list and post sliders
display-post-types
Display list of posts, pages or any custom post types anywhere using block and widget. Show as grid, list or posts slider.
Display A Post Developer Profile
2 plugins · 30 total installs
How We Detect Display A Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
get-post-content-titlepostread-more-guid<div class="get-post-content-</h3><div class="post" style="color:<em><a class="read-more-guid" href="