Insert post from front-end with featured image Security & Risk Analysis

wordpress.org/plugins/insert-post-from-front-end-with-featured-image

This plugin is created for insert post from front-end, Using this plugin we can insert any type of post from front-end with featured image.

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Jan 28, 2020
commentscustom-postsnewsreviewstestimonial
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Insert post from front-end with featured image Safe to Use in 2026?

Generally Safe

Score 85/100

Insert post from front-end with featured image has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "insert-post-from-front-end-with-featured-image" plugin v1.0.0 exhibits a generally positive security posture based on the static analysis. The absence of direct SQL injection vulnerabilities due to the exclusive use of prepared statements and the lack of known CVEs are significant strengths. The plugin also demonstrates good practices by including a nonce check, which helps prevent CSRF attacks.

However, a critical concern arises from the complete lack of output escaping. This means that any data displayed to users, particularly if it originates from user input or external sources, is not properly sanitized. This could lead to Cross-Site Scripting (XSS) vulnerabilities, allowing an attacker to inject malicious scripts into the site, which can then be executed in the browser of other users. Furthermore, the absence of capability checks on the identified shortcode is a weakness. While there are no unprotected entry points listed, a shortcode without proper capability checks could be leveraged by users with insufficient privileges to perform actions they shouldn't be able to.

Given the clean vulnerability history and the use of prepared statements, the plugin appears to have been developed with security in mind. However, the unescaped output and the potential for privilege escalation through the shortcode are significant risks that require immediate attention to improve the plugin's overall security. Addressing these areas would bring the plugin's security much closer to best practices.

Key Concerns

  • Unescaped output found
  • No capability checks on shortcode
Vulnerabilities
None known

Insert post from front-end with featured image Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Insert post from front-end with featured image Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Insert post from front-end with featured image Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[Insert_post_from_frontEnd] includes\class-insert_post_from_front_end.php:173
WordPress Hooks 5
actionplugins_loadedincludes\class-insert_post_from_front_end.php:139
actionadmin_enqueue_scriptsincludes\class-insert_post_from_front_end.php:154
actionadmin_enqueue_scriptsincludes\class-insert_post_from_front_end.php:155
actionwp_enqueue_scriptsincludes\class-insert_post_from_front_end.php:170
actionwp_enqueue_scriptsincludes\class-insert_post_from_front_end.php:171
Maintenance & Trust

Insert post from front-end with featured image Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedJan 28, 2020
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Insert post from front-end with featured image Developer Profile

Mohsin Khan

3 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Insert post from front-end with featured image

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/insert-post-from-front-end-with-featured-image/css/insert_post_from_front_end-admin.css/wp-content/plugins/insert-post-from-front-end-with-featured-image/js/insert_post_from_front_end-admin.js
Version Parameters
insert_post_from_front_end?ver=1.0.0insert_post_from_front_end-admin.css?ver=1.0.0insert_post_from_front_end-admin.js?ver=1.0.0

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Insert post from front-end with featured image