
Frontend Add Post Security & Risk Analysis
wordpress.org/plugins/frontend-add-postAdd a post on frontend with ajax and simple and elegant look also list down published post with simple yet attractive layout.
Is Frontend Add Post Safe to Use in 2026?
Generally Safe
Score 85/100Frontend Add Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "frontend-add-post" plugin version 1.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The code also demonstrates good practices with 100% of SQL queries using prepared statements and 80% of output properly escaped. The presence of a nonce check and a reasonable attack surface with no apparent unprotected entry points further contribute to its security. The plugin's vulnerability history is entirely clean, with no recorded CVEs, suggesting a well-maintained and secure codebase over time.
However, a notable concern arises from the complete absence of capability checks for any of its entry points. While nonce checks provide a layer of protection against CSRF attacks, they do not restrict access to authenticated users with specific roles or permissions. This lack of capability checks means that any authenticated user, regardless of their privileges, could potentially interact with the AJAX handlers. This could lead to unintended actions or information disclosure if the AJAX handlers are not intrinsically secured against unauthorized use by lower-privileged users. Despite the clean slate of vulnerabilities and good coding practices, this oversight represents the primary area for improvement in the plugin's security. The plugin is overall secure in its coding practices, but the missing capability checks are a significant weakness that needs to be addressed to ensure true authorization.
Key Concerns
- Missing capability checks on AJAX handlers
- Unescaped output on 1 out of 5 outputs
Frontend Add Post Security Vulnerabilities
Frontend Add Post Code Analysis
Output Escaping
Frontend Add Post Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Frontend Add Post Maintenance & Trust
Maintenance Signals
Community Trust
Frontend Add Post Alternatives
Sitemap by BestWebSoft – WordPress XML Site Map Page Generator Plugin
google-sitemap-plugin
Generate and add XML sitemap to WordPress website. Help search engines index your blog.
User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration
wp-user-frontend
Create forms, guest posts, subscriptions, user directory, user registration, membership, frontend posts, profile builder, content restriction rules.
Frontend Admin by DynamiApps
acf-frontend-form-element
This awesome plugin allows you to easily display frontend forms on your site so your clients can easily edit content by themselves from the frontend.
User Submitted Posts – Enable Users to Submit Posts from the Front End
user-submitted-posts
Enable visitors to submit posts and images from the front-end of your site. Many features including anti-spam security, content restriction, and more.
Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress
easy-post-submission
Enable users to submit posts and manage profiles from the front-end. Ideal for news, magazines, and creative platforms.
Frontend Add Post Developer Profile
6 plugins · 5K total installs
How We Detect Frontend Add Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/frontend-add-post/js/fap-main.js/wp-content/plugins/frontend-add-post/js/bootstrap.min.js/wp-content/plugins/frontend-add-post/js/bootstrap-tagsinput.js/wp-content/plugins/frontend-add-post/css/bootstrap.min.css/wp-content/plugins/frontend-add-post/css/bootstrap-tagsinput.css/wp-content/plugins/frontend-add-post/css/fap-style.cssjs/fap-main.jsjs/bootstrap.min.jsjs/bootstrap-tagsinput.jsfap-mainbootstrap-minbootstrap-tagsinputbootstrap-min-cssbootstrap-tagsinputfap-styleHTML / DOM Fingerprints
quick-post-forminput-wrapperform-panel-2row-fluidrow-portfolioauthor-mainauthor-avatarauthor-details+5 more<!-- AJAX URL is set globally in WordPress --><!-- AJAX URL is set globally in WordPress -->data-role='tagsinput'id='quick-post-form'id='post-title'id='tagsinput'id='postsend'id='loading-image'+1 morefapajax/wp-json/wp/v2/posts<form id='quick-post-form'><div class='input-wrapper'><input type='text' id='post-title' name='post-title' placeholder='Write here...'/><div class='form-panel-2'>