
L7 Display Posts Security & Risk Analysis
wordpress.org/plugins/l7-display-postsEfficiently show posts by tag or category using a simple shortcode. Utilizes caching for greater speed and fewer database calls.
Is L7 Display Posts Safe to Use in 2026?
Generally Safe
Score 85/100L7 Display Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'l7-display-posts' plugin version 0.1.1 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, SQL queries performed exclusively via prepared statements, and a high percentage of properly escaped output are positive indicators. Furthermore, the plugin has no known vulnerabilities (CVEs) and no reported vulnerabilities in its history, suggesting a history of secure development. The limited attack surface, with only one shortcode and no AJAX handlers, REST API routes, or cron events, further enhances its security. The lack of external HTTP requests and file operations also reduces potential attack vectors.
However, there are a few areas that warrant attention. The plugin does not implement any nonce checks or capability checks. While the current attack surface is minimal and the shortcode may not inherently require these, it represents a missed opportunity for robust security, especially if the plugin's functionality were to expand or its shortcode's output became more complex or user-controlled in future versions. The absence of taint analysis results is noted, though this could be due to the limited complexity or lack of user-supplied input processing within the analyzed code, rather than an explicit security flaw.
In conclusion, 'l7-display-posts' v0.1.1 appears to be a secure plugin due to its clean code practices, lack of known vulnerabilities, and small attack surface. The primary area for improvement lies in implementing proper authorization checks, such as nonce and capability checks, to further harden the plugin against potential future threats or expansions of its functionality.
Key Concerns
- Missing nonce checks
- Missing capability checks
L7 Display Posts Security Vulnerabilities
L7 Display Posts Code Analysis
Output Escaping
L7 Display Posts Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
L7 Display Posts Maintenance & Trust
Maintenance Signals
Community Trust
L7 Display Posts Alternatives
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Plug & Play
plug-and-play
Plug and Play our feautures and turn your WordPress Blog into a Highly Interactive, Elegant and Secure Blog.
Custom Post Count At A Glance
custom-post-count-at-a-glance
Display the count of custom posts in the WordPress dashboard in the 'At a glance' widget, like posts, pages and comment count.
Easy Timeline
easy-timeline
Add a timeline to your website using a simple shortcode.
Paged Post List Shortcode
paged-post-list-shortcode
Display a list of items (posts or pages) with pagination. Use shortcode: [list_posts_paged]
L7 Display Posts Developer Profile
4 plugins · 140 total installs
How We Detect L7 Display Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/l7-display-posts/assets/css/primary-tag-plugin.min.cssHTML / DOM Fingerprints
[Display Poststag=cat=posts=