
Encrypted Post Type Security & Risk Analysis
wordpress.org/plugins/encrypted-post-typeEncrypted Post Type provides a custom post type where the content of each post is encrypted.
Is Encrypted Post Type Safe to Use in 2026?
Generally Safe
Score 85/100Encrypted Post Type has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "encrypted-post-type" v1.0.0 plugin exhibits a very strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. The code analysis reveals a commitment to secure coding practices, with all detected SQL queries utilizing prepared statements and a high percentage of output being properly escaped. The lack of file operations and external HTTP requests further reduces potential risks.
While the overall picture is positive, there are a couple of minor areas for attention. The taint analysis identified two flows with unsanitized paths, which, although not resulting in critical or high severity issues in this instance, represents a potential vector for future vulnerabilities if not addressed. Furthermore, the absence of nonce checks is a concern, as it suggests that actions triggered by this plugin might not have the necessary protection against Cross-Site Request Forgery (CSRF) attacks, especially if any actions are performed on the backend without proper authorization.
The plugin's vulnerability history, being entirely clear, is a significant strength, indicating a mature and well-maintained codebase to date. In conclusion, "encrypted-post-type" v1.0.0 appears to be a securely developed plugin with excellent adherence to best practices. The primary areas for improvement lie in addressing the identified unsanitized paths and implementing nonce checks to further harden its defenses against potential attacks.
Key Concerns
- Taint flows with unsanitized paths found
- No nonce checks implemented
Encrypted Post Type Security Vulnerabilities
Encrypted Post Type Code Analysis
Output Escaping
Data Flow Analysis
Encrypted Post Type Attack Surface
WordPress Hooks 19
Maintenance & Trust
Encrypted Post Type Maintenance & Trust
Maintenance Signals
Community Trust
Encrypted Post Type Alternatives
WP PGP Encrypted Emails
wp-pgp-encrypted-emails
Signs and encrypts emails using PGP/GPG keys or X.509 certificates. Provides OpenPGP and S/MIME functions via WordPress plugin API.
CryptNote Secure Links
cryptnote-secure-links
Integrates CryptNote.pro to generate encrypted links directly from the WordPress dashboard and replace emails with secure links.
My Private Site
jonradio-private-site
Make your WordPress site private with one click for family, projects, or teams. Protection for content, login, and registration.
Restricted Site Access
restricted-site-access
Limit access to visitors who are logged in or allowed by IP addresses. Includes many options for handling blocked visitors.
CryptX
cryptx
No more SPAM by spiders scanning your site for email addresses!
Encrypted Post Type Developer Profile
1 plugin · 0 total installs
How We Detect Encrypted Post Type
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/encrypted-post-type/assets/css/admin/admin-style.css/wp-content/plugins/encrypted-post-type/assets/js/admin/onEditScreen.js/wp-content/plugins/encrypted-post-type/assets/js/admin/onEditScreen.jsencrypted-post-type?ver=1.0.0HTML / DOM Fingerprints
en_p_t/wp-json/wp/v2/en_p_t