
LH Logged In Post Status Security & Risk Analysis
wordpress.org/plugins/lh-logged-in-post-statusAllows you to restrict access to posts, pges etc to logged in users only.
Is LH Logged In Post Status Safe to Use in 2026?
Generally Safe
Score 85/100LH Logged In Post Status has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'lh-logged-in-post-status' version 1.09 presents a strong initial security posture based on the provided static analysis. The absence of any identified attack surface (AJAX handlers, REST API routes, shortcodes, cron events) significantly limits the potential entry points for malicious actors. Furthermore, the code analysis reveals good practices such as the absence of dangerous functions, file operations, and external HTTP requests. SQL queries are correctly prepared, and a high percentage of output is properly escaped. The presence of capability checks also indicates an effort to enforce permissions.
However, a notable concern arises from the complete lack of nonce checks. While the attack surface is currently zero, this absence leaves the plugin vulnerable to Cross-Site Request Forgery (CSRF) attacks should any entry points be introduced in future updates or if specific configurations bypass the current zero attack surface. The taint analysis reporting zero flows is positive, but this could also be a reflection of a very limited code base or functionality. The vulnerability history being completely clear is a significant strength, suggesting a well-maintained and secure development history for this plugin.
In conclusion, 'lh-logged-in-post-status' v1.09 exhibits a generally secure design with minimal immediate risks due to its limited attack surface and good coding practices in areas like SQL and output escaping. The primary weakness is the complete omission of nonce checks, which, while not currently exploitable due to the zero attack surface, represents a potential security debt that could become a problem in the future. The absence of any past vulnerabilities is a strong indicator of the plugin's reliability.
Key Concerns
- Missing nonce checks
LH Logged In Post Status Security Vulnerabilities
LH Logged In Post Status Code Analysis
SQL Query Safety
Output Escaping
LH Logged In Post Status Attack Surface
WordPress Hooks 20
Maintenance & Trust
LH Logged In Post Status Maintenance & Trust
Maintenance Signals
Community Trust
LH Logged In Post Status Alternatives
LH Archived Post Status
lh-archived-post-status
Allows posts and pages to be archived so you can remove content from the main loop and feed without having to trash it.
LH Inclusive Private Pages
lh-inclusive-private-pages
Extends the CRM possibilities for wordpress by allowing private posts/pages, and other CPt´s to be included in menus and also as the parent of other p …
Post Status Indicator
post-status-indicator
Allow color customization in WordPress admin for the publish state of your content.
Sortable Word Count Reloaded
sortable-word-count-reloaded
Adds a sortable column to the posts and pages admin list with the word count of each page/post.
Bulk Edit YOAST SEO fields in Spreadsheet
wp-sheet-editor-yoast-seo
Bulk Edit posts, pages, and WooCommerce products YOAST SEO fields using a spreadsheet.
LH Logged In Post Status Developer Profile
77 plugins · 15K total installs
How We Detect LH Logged In Post Status
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lh-logged-in-post-status/includes/wp-statuses/js/admin.js/wp-content/plugins/lh-logged-in-post-status/includes/wp-statuses/css/admin.css/wp-content/plugins/lh-logged-in-post-status/includes/wp-statuses/js/admin.jslh-logged-in-post-status/includes/wp-statuses/css/admin.css?ver=lh-logged-in-post-status/includes/wp-statuses/js/admin.js?ver=HTML / DOM Fingerprints
lh-logged-in-post-status-admin-wrap<!-- LH Logged in post status plugin class -->data-plugin-name="LH Logged in post status"data-plugin-uri="https://lhero.org/portfolio/lh-logged-in-post-status/"LH_logged_in_post_status_plugin