FlairBees Post Word Filter & Replace Security & Risk Analysis

wordpress.org/plugins/flairbees-post-word-filter-and-replace

An easy to use plugin that allows you to filter an replace words/strings on your site post's without editing WordPress

10 active installs v1.1.0 PHP + WP 4.6+ Updated Oct 9, 2025
find-and-replacereplaceword-filter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is FlairBees Post Word Filter & Replace Safe to Use in 2026?

Generally Safe

Score 100/100

FlairBees Post Word Filter & Replace has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "flairbees-post-word-filter-and-replace" plugin v1.1.0 demonstrates a generally good security posture based on the provided static analysis and vulnerability history. The absence of any detected CVEs, coupled with a clean taint analysis and a strong adherence to prepared statements for SQL queries, indicates a diligent approach to secure coding. The presence of both nonce and capability checks is also a positive sign, suggesting an awareness of basic WordPress security principles.

However, a significant concern arises from the output escaping metric. With 69% of outputs properly escaped, this leaves 31% of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks. While the static analysis shows no immediate critical or high-severity taint flows, an unescaped output is a direct pathway for XSS, which can have serious consequences. The plugin also presents a very small attack surface, which is positive, but the lack of specific details on the 0 AJAX handlers, REST API routes, and shortcodes makes it difficult to definitively rule out potential issues if they were to be introduced in future versions without proper sanitization.

In conclusion, the plugin is off to a strong start with its security practices. The lack of historical vulnerabilities is commendable. The primary area for improvement and immediate attention is the output escaping. Addressing the unescaped output will significantly bolster the plugin's security and mitigate a clear risk of XSS vulnerabilities. Further development should prioritize maintaining the current level of secure coding practices, particularly in output handling.

Key Concerns

  • Unescaped output detected (31%)
Vulnerabilities
None known

FlairBees Post Word Filter & Replace Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FlairBees Post Word Filter & Replace Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
11 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

69% escaped16 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
handleForm (word-filter.php:89)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FlairBees Post Word Filter & Replace Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuword-filter.php:22
actionadmin_initword-filter.php:23
filterthe_contentword-filter.php:25
Maintenance & Trust

FlairBees Post Word Filter & Replace Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 9, 2025
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

FlairBees Post Word Filter & Replace Developer Profile

Imran Hosein Khan Joy

2 plugins · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FlairBees Post Word Filter & Replace

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flairbees-post-word-filter-and-replace/assets/css/style.css
Version Parameters
flairbees-post-word-filter-and-replace/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
descriptio
FAQ

Frequently Asked Questions about FlairBees Post Word Filter & Replace