
Filter Bar Custom Post Type Security & Risk Analysis
wordpress.org/plugins/filter-bar-custom-post-typeUn plugin simple pour filtrer les Types De Publications Personnalisés par catégories avec animation et support multi-instances.
Is Filter Bar Custom Post Type Safe to Use in 2026?
Generally Safe
Score 100/100Filter Bar Custom Post Type has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The filter-bar-custom-post-type plugin version 1.0.6 demonstrates a strong security posture based on the provided static analysis. It effectively avoids dangerous functions and file operations, and all identified SQL queries utilize prepared statements. The high percentage of properly escaped output further mitigates cross-site scripting (XSS) risks. There are no registered vulnerabilities in its history, which is a positive indicator of the development team's attention to security.
However, the analysis does highlight some areas for improvement. The absence of nonce checks and capability checks across all entry points, particularly the single shortcode, presents a potential weakness. While the attack surface is currently small (one shortcode), any future expansion without implementing these fundamental security measures could introduce vulnerabilities. The fact that there are no known CVEs is encouraging, but the lack of robust input validation and authorization mechanisms on the shortcode means that potential issues could exist if not carefully managed.
In conclusion, while the plugin has commendable security practices in place, particularly regarding SQL and output escaping, the lack of nonces and capability checks on its shortcode is a notable concern. This leaves a potential avenue for attackers if the shortcode's functionality involves sensitive operations or user-controlled data. The plugin's vulnerability history is clean, but this should not be a reason to neglect essential security controls.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
Filter Bar Custom Post Type Security Vulnerabilities
Filter Bar Custom Post Type Code Analysis
Output Escaping
Filter Bar Custom Post Type Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Filter Bar Custom Post Type Maintenance & Trust
Maintenance Signals
Community Trust
Filter Bar Custom Post Type Alternatives
Radius Portfolio – Filterable Grid, Gallery & Slider Portfolio
tlp-portfolio
A simple and powerful WordPress portfolio plugin to showcase your creative work beautifully with different ways.
WP Ultimate Post Grid
wp-ultimate-post-grid
Easily create filterable responsive grids for your posts, pages or custom post types
Filter Gallery
filter-gallery
Build a responsive filter gallery for your portfolio. Organize images with filters in a stunning grid or masonry layout easily.
Zilla Portfolio
zillaportfolio
A complete portfolio plugin for creative folks
GS Portfolio – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more
gs-portfolio
Showcase your work with GS Portfolio – create filterable grids, sliders & stylish layouts anywhere on your site using simple shortcodes.
Filter Bar Custom Post Type Developer Profile
6 plugins · 140 total installs
How We Detect Filter Bar Custom Post Type
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/filter-bar-custom-post-type/css/fbcpt-style.css/wp-content/plugins/filter-bar-custom-post-type/build/index.js/wp-content/plugins/filter-bar-custom-post-type/build/index.css/wp-content/plugins/filter-bar-custom-post-type/build/index.jsfilter-bar-custom-post-type/css/fbcpt-style.css?ver=filter-bar-custom-post-type/build/index.js?ver=filter-bar-custom-post-type/build/index.css?ver=HTML / DOM Fingerprints
fbcpt-style<!-- Filter Bar Custom Post Type [REV:1.0.6] --><!-- DÉFINITION DES CONSTANTES --><!-- On charge le fichier de traduction --><!-- CHARGEMENT STYLES DU PLUGIN -->+23 moreid="filter-bar-cpt-script-js-extra"fbcptColorPaletteFBCPT_PLUGIN_VERSIONFILTER_BAR_CUSTOM_POST_TYPE_URLFBCPT_PLUGIN_PATH_NAME