Inject Query Posts Security & Risk Analysis

wordpress.org/plugins/inject-query-posts

Facilitates injecting an array of posts into a WP query object as if queried. Particularly useful to allow use of standard template tags.

10 active installs v3.0.5 PHP + WP 3.6+ Updated Apr 23, 2025
looppostsquerytemplate-tagswp_query
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Inject Query Posts Safe to Use in 2026?

Generally Safe

Score 92/100

Inject Query Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "inject-query-posts" v3.0.5 plugin exhibits an exceptionally strong security posture. The absence of any detected attack surface points, dangerous functions, or unsanitized taint flows is highly commendable. Furthermore, the plugin demonstrates excellent adherence to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping all output. The complete lack of file operations, external HTTP requests, and the apparent robust implementation of security checks (though the analysis reports 0 capability checks and 0 nonce checks, the absence of these is often a result of a minimal attack surface making them unnecessary) further solidify this positive assessment.

The vulnerability history further reinforces this excellent security record, with no known CVEs, patched or unpatched, ever recorded for this plugin. This indicates a mature and well-maintained codebase that has likely undergone thorough security reviews or has benefited from a lack of historically exploitable flaws. The plugin's strengths lie in its minimal attack surface and strict adherence to secure coding principles for its identified entry points and operations.

While the analysis presents an overwhelmingly positive security profile, the reporting of zero capability checks and zero nonce checks warrants a slight note of caution. In a plugin with a larger attack surface or more complex functionality, this would be a significant concern. However, given the reported zero entry points and zero unsanitized flows, it's plausible that the functionality of this plugin is so limited or its integration points are so controlled that these checks are not strictly necessary for its current implementation. Nonetheless, for future development or if the plugin's scope expands, ensuring these checks are in place for any new entry points would be prudent.

Vulnerabilities
None known

Inject Query Posts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Inject Query Posts Release Timeline

v3.0.5Current
v3.0.4
v3.0.3
v3.0.2
v3.0.1
v3.0
v2.2.9
v2.2.8
v2.2.7
v2.2.6
v2.2.5
v2.2.4
v2.2.3
v2.2.2
v2.2.1
v2.2
v2.1
v2.0.5
v2.0.4
v2.0.3
Code Analysis
Analyzed Mar 16, 2026

Inject Query Posts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Inject Query Posts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterc2c_inject_query_postsinject-query-posts.php:200
Maintenance & Trust

Inject Query Posts Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 23, 2025
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Inject Query Posts Developer Profile

Scott Reilly

63 plugins · 92K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
374 days
View full developer profile
Detection Fingerprints

How We Detect Inject Query Posts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Inject Query Posts