
Hidden Posts Security & Risk Analysis
wordpress.org/plugins/hidden-postsHide a limited number of specified posts from the hompage.
Is Hidden Posts Safe to Use in 2026?
Generally Safe
Score 85/100Hidden Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hidden-posts" plugin version 0.1 exhibits an excellent security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests is highly commendable. The presence of a nonce check, while a positive sign, is somewhat weakened by the lack of corresponding capability checks. The plugin's attack surface is effectively zero, with no AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing potential entry points for malicious activity. Taint analysis also reveals no critical or high severity vulnerabilities, reinforcing the impression of a secure codebase.
The vulnerability history is equally impressive, with zero recorded CVEs of any severity. This, combined with the static analysis findings, suggests that the developers have implemented robust security practices. However, the complete lack of capability checks on the single nonce check is a minor concern. While the attack surface is minimal, ensuring proper authorization for any potential administrative actions that might utilize the nonce is crucial for comprehensive security. Overall, this plugin appears to be very secure, with the only area for minor improvement being the explicit implementation of capability checks.
Key Concerns
- Missing capability checks on nonce
Hidden Posts Security Vulnerabilities
Hidden Posts Code Analysis
Hidden Posts Attack Surface
WordPress Hooks 3
Maintenance & Trust
Hidden Posts Maintenance & Trust
Maintenance Signals
Community Trust
Hidden Posts Alternatives
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Duplicate Post
copy-delete-posts
Duplicate post
Hidden Posts Developer Profile
4 plugins · 70 total installs
How We Detect Hidden Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
superawesome-box