
KD Post Tile Listview Security & Risk Analysis
wordpress.org/plugins/kd-post-tile-listviewFeatures Simple and fast configuration Shortcode Future Features Style options Multiple categories Query options A plugin to list posts in til …
Is KD Post Tile Listview Safe to Use in 2026?
Generally Safe
Score 100/100KD Post Tile Listview has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "kd-post-tile-listview" v0.2.6 exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, file operations, or external HTTP requests, which are common vectors for exploitation. The code also demonstrates excellent output escaping practices, with 100% of outputs being properly handled, mitigating the risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of known CVEs and a clean vulnerability history further contribute to a positive security outlook.
However, there are a few areas that warrant attention. The lack of nonce checks and capability checks is a significant concern, especially given that the plugin has a shortcode entry point. While there are no explicitly unprotected AJAX handlers or REST API routes, a shortcode without proper authorization checks can still be leveraged in certain attack scenarios. Furthermore, half of the SQL queries are not using prepared statements. While the total number of SQL queries is low, this practice can open the door to SQL injection vulnerabilities if data originates from user input without proper sanitization, which is not fully assessed by the provided taint analysis.
In conclusion, the plugin's strengths lie in its robust output escaping and lack of critical code signals like dangerous functions or vulnerable external requests. The primary weaknesses are the absence of nonce/capability checks on its sole entry point (the shortcode) and the use of raw SQL in some queries. Addressing these points would significantly enhance the plugin's overall security.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- 50% of SQL queries not using prepared statements
KD Post Tile Listview Security Vulnerabilities
KD Post Tile Listview Code Analysis
SQL Query Safety
Output Escaping
KD Post Tile Listview Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
KD Post Tile Listview Maintenance & Trust
Maintenance Signals
Community Trust
KD Post Tile Listview Alternatives
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts
post-carousel
Display posts, pages, and taxonomies in beautiful carousel, slider, and grid layouts with advanced filtering. Customizable, Developer-friendly.
Custom Layouts – Post + Product grids made easy
custom-layouts
Build a list or grid layout of any post type (posts, products, pages + more).
GS Posts Grid – Recent Posts, Category Posts, Post Filter, Slider & List
posts-grid
GS Posts Grid – A flexible plugin to display posts in Grid, Masonry, Slider, Popup, List, Card, Table, Filter & Justified Gallery views.
WP Recent Posts Extended
wp-recent-posts-extended
Este widget muestra los últimos artículos publicados agrupados por categorías.
KD Post Tile Listview Developer Profile
1 plugin · 0 total installs
How We Detect KD Post Tile Listview
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kd-post-tile-listview/assets/css/admin-style.css/wp-content/plugins/kd-post-tile-listview/assets/css/style.css/wp-content/plugins/kd-post-tile-listview/templates/assets/single-tiles.cssHTML / DOM Fingerprints
tile-listtilefullhalfbackgroundcolorheadcategorylinkstyle[tiles_portfolio]