Display Posts Shortcode, Current Page Custom Field Add-On Security & Risk Analysis

wordpress.org/plugins/display-posts-shortcode-current-page-custom-field-add-on

Convert "current" as the current page ID when using the display posts shortcode to query custom fields.

10 active installs v1.0 PHP + WP 3.0+ Updated Oct 9, 2014
displaylistpagepagesposts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Display Posts Shortcode, Current Page Custom Field Add-On Safe to Use in 2026?

Generally Safe

Score 85/100

Display Posts Shortcode, Current Page Custom Field Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin 'display-posts-shortcode-current-page-custom-field-add-on' version 1.0 exhibits an excellent security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The absence of file operations, external HTTP requests, and any indication of taint analysis issues further solidifies this strong foundation. The plugin also demonstrates good practices by having no identifiable attack surface points (AJAX, REST API, shortcodes, cron events) that are unprotected by authentication or capability checks.

The vulnerability history is completely clear, with no known CVEs recorded, indicating a lack of past security issues. This, coupled with the clean static analysis, suggests the developers are prioritizing security. However, it is worth noting the complete absence of nonces and capability checks. While not an immediate risk due to the lack of entry points, if future versions introduce new entry points or functionality, these checks will become crucial for maintaining security. Overall, this plugin appears very secure with a strong emphasis on best practices, though the complete lack of any checks could be a point of future consideration.

Vulnerabilities
None known

Display Posts Shortcode, Current Page Custom Field Add-On Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Display Posts Shortcode, Current Page Custom Field Add-On Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Display Posts Shortcode, Current Page Custom Field Add-On Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterdisplay_posts_shortcode_argsdsp-current-page-custom-field-addon.php:44
Maintenance & Trust

Display Posts Shortcode, Current Page Custom Field Add-On Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedOct 9, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Display Posts Shortcode, Current Page Custom Field Add-On Developer Profile

Itamar Ostricher

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Display Posts Shortcode, Current Page Custom Field Add-On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Display Posts Shortcode, Current Page Custom Field Add-On