
Post Kinds Security & Risk Analysis
wordpress.org/plugins/indieweb-post-kindsEver want to reply to someone else's post with a post on your own site? Or to "like" someone else's post, but with your own site?
Is Post Kinds Safe to Use in 2026?
Generally Safe
Score 92/100Post Kinds has a strong security track record. Known vulnerabilities have been patched promptly.
The "indieweb-post-kinds" plugin v3.7.3 presents a mixed security posture. While it demonstrates good practices in several areas, such as using prepared statements for all SQL queries and having no known critical or high-severity vulnerabilities in its history, there are significant concerns arising from the static analysis.
The plugin exposes one REST API route that lacks permission callbacks, creating an unprotected entry point into the application. This is a critical flaw as it means any unauthenticated user could potentially interact with this endpoint. Although the static analysis did not reveal any dangerous functions, unescaped output, or unsanitized taint flows, the presence of an unprotected API route is a substantial risk that could be exploited for various malicious purposes, depending on the functionality of that route.
The vulnerability history, while dated, shows a past medium-severity Cross-Site Scripting (XSS) vulnerability. The lack of recent vulnerabilities and the existence of only one medium-severity one from 2015 could indicate improved development practices over time or simply a lack of recent, impactful discoveries. However, the current static analysis findings, particularly the unprotected REST API route, overshadow the historical record. The plugin's overall security is moderately compromised by this single, significant exposure.
Key Concerns
- Unprotected REST API route
- Low output escaping rate (42%)
- Dated vulnerability history (2015)
Post Kinds Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Post Kinds < 1.3.1.1 - Cross-Site Scripting
Post Kinds Code Analysis
Output Escaping
Post Kinds Attack Surface
REST API Routes 1
WordPress Hooks 72
Maintenance & Trust
Post Kinds Maintenance & Trust
Maintenance Signals
Community Trust
Post Kinds Alternatives
Webmention
webmention
Enable conversation across the web.
IndieWeb
indieweb
IndieWeb for WordPress!
Swifty Bar, sticky bar by WPGens
swifty-bar
Adds sticky bar at the bottom of post that shows category,post title, author, time needed to read article, share buttons and previous/next post links
IndieBlocks
indieblocks
Use blocks, and, optionally, "short-form" post types to easily "IndieWebify" your WordPress site.
Mastodon Auto Share
wp-mastodon-share
Publish your posts on your Mastodon's instance.
Post Kinds Developer Profile
5 plugins · 720 total installs
How We Detect Post Kinds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/indieweb-post-kinds/css/kind.min.css/wp-content/plugins/indieweb-post-kinds/css/kind.admin.min.cssindieweb-post-kinds/css/kind.min.css?ver=indieweb-post-kinds/css/kind.admin.min.css?ver=HTML / DOM Fingerprints
kind-menu-widgetkind-post-widgetdata-kind/wp-json/parse-this/