
Fahim Project & Post Type Builder Security & Risk Analysis
wordpress.org/plugins/fahim-project-post-type-builderFahim Project & Post Type Builder
Is Fahim Project & Post Type Builder Safe to Use in 2026?
Generally Safe
Score 100/100Fahim Project & Post Type Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fahim-project-post-type-builder" plugin v2.0.0 exhibits a generally strong security posture, with excellent adherence to secure coding practices. All identified AJAX handlers are protected by authentication checks, and there are no unprotected REST API routes, shortcodes, or cron events, indicating a well-secured attack surface. The plugin also demonstrates a commitment to data integrity by using prepared statements for all SQL queries and properly escaping a very high percentage of its output. The absence of file operations and external HTTP requests further reduces potential attack vectors.
However, there are a couple of concerning areas highlighted by the taint analysis. Specifically, two flows with unsanitized paths have been identified with high severity. While the plugin has no recorded vulnerability history, the presence of these unsanitized paths in the static analysis warrants attention as they could potentially lead to vulnerabilities if not handled correctly, especially concerning path traversal. The plugin also includes bundled libraries (DataTables, Select2) which, if outdated, could introduce transitive vulnerabilities, though this is not explicitly stated in the provided data. The inclusion of nonce checks, while present, is not universal across all entry points, which is a minor concern for certain types of AJAX interactions.
In conclusion, "fahim-project-post-type-builder" v2.0.0 is a well-secured plugin with a strong foundation in secure coding practices. The primary area for improvement lies in thoroughly investigating and sanitizing the identified unsanitized path flows. Addressing these specific taint issues would elevate the plugin's security to an even higher standard. The lack of past vulnerabilities is a positive indicator, but ongoing vigilance and code review are always recommended.
Key Concerns
- High severity taint flow with unsanitized paths (2 instances)
- Bundled libraries (DataTables, Select2) may be outdated
- Nonce checks are present but not universal
Fahim Project & Post Type Builder Security Vulnerabilities
Fahim Project & Post Type Builder Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Fahim Project & Post Type Builder Attack Surface
AJAX Handlers 18
WordPress Hooks 10
Maintenance & Trust
Fahim Project & Post Type Builder Maintenance & Trust
Maintenance Signals
Community Trust
Fahim Project & Post Type Builder Alternatives
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
Sydney Toolbox
sydney-toolbox
Registers custom post types and custom fields for the Sydney theme
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Fahim Project & Post Type Builder Developer Profile
2 plugins · 50 total installs
How We Detect Fahim Project & Post Type Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fahim-project-post-type-builder/assets/css/fahimptb-styles.css/wp-content/plugins/fahim-project-post-type-builder/assets/css/fahimptb-admin.css/wp-content/plugins/fahim-project-post-type-builder/assets/css/dataTables.bootstrap4.min.css/wp-content/plugins/fahim-project-post-type-builder/assets/css/datatables.min.css/wp-content/plugins/fahim-project-post-type-builder/assets/js/jquery.dataTables.min.js/wp-content/plugins/fahim-project-post-type-builder/assets/js/dataTables.bootstrap4.min.js/wp-content/plugins/fahim-project-post-type-builder/assets/css/select2.min.css/wp-content/plugins/fahim-project-post-type-builder/assets/js/select2.min.js+1 more/wp-content/plugins/fahim-project-post-type-builder/assets/js/jquery.dataTables.min.js/wp-content/plugins/fahim-project-post-type-builder/assets/js/dataTables.bootstrap4.min.js/wp-content/plugins/fahim-project-post-type-builder/assets/js/select2.min.js/wp-content/plugins/fahim-project-post-type-builder/assets/js/fahimptb-script.js/wp-content/plugins/fahim-project-post-type-builder/assets/css/fahimptb-styles.css?ver=/wp-content/plugins/fahim-project-post-type-builder/assets/css/fahimptb-admin.css?ver=/wp-content/plugins/fahim-project-post-type-builder/assets/js/fahimptb-script.js?ver=HTML / DOM Fingerprints
fahimptb-headerbarfahimptb-headerbar-field-editorfahimptb-headerbar-innerfahimptb-headerbar-contentfahimptb-page-titlefahimptb_ajax_object