
LH Posse Security & Risk Analysis
wordpress.org/plugins/lh-posseA flexible way to syndicate your content to Facebook, Twitter, or anywhere via IFTTT using customised feeds.
Is LH Posse Safe to Use in 2026?
Generally Safe
Score 85/100LH Posse has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lh-posse" plugin v1.03 exhibits a concerning security posture despite the absence of known vulnerabilities or critical findings in static and taint analysis. The most significant weakness lies in the complete lack of output escaping, meaning all 44 identified output points are potentially vulnerable to cross-site scripting (XSS) attacks. This widespread vulnerability, coupled with the absence of nonce and capability checks, exposes the plugin to various client-side attacks if an attacker can inject malicious input that is later rendered without sanitization. While the plugin shows good practice by using prepared statements for its single SQL query and has no recorded history of CVEs, these strengths are significantly overshadowed by the critical flaw in output handling and the absence of essential security checks for its attack surface, which is currently zero but could easily increase if functionality is added without proper security considerations. The plugin's current lack of an attack surface is a positive sign, but it's crucial to address the output escaping issue immediately to prevent future vulnerabilities.
Key Concerns
- 0% of outputs properly escaped
- 0 Nonce checks present
- 0 Capability checks present
LH Posse Security Vulnerabilities
LH Posse Release Timeline
LH Posse Code Analysis
SQL Query Safety
Output Escaping
LH Posse Attack Surface
WordPress Hooks 5
Maintenance & Trust
LH Posse Maintenance & Trust
Maintenance Signals
Community Trust
LH Posse Alternatives
Metro Style Social Widget
metro-style-social-widget
Metro Style Social Network Widget
Feeder Ninja: Create and add RSS & Social feeds to your website on-the-fly
feeder-ninja-feed
The best tool for adding RSS & Social media feeds to your Wordpress website. Powered by Common Ninja.
BVD Easy Social Feeds & Images
bvd-easy-social-feeds-images
A WordPress plugin to display any public Facebook, Twitter, or Instagram feed on your website.
Civic Social Feeds
civic-social-feeds
This plugin provides Wordpress administrators a configuration page to set up credentials for various social networks in order to access API’s and gets …
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds
facebook-pagelike-widget
Floating Social Media Icons, Sticky Share Buttons, Facebook Feeds, & Popup builder. Also, create Call, Email, SMS, & Contact buttons to increa …
LH Posse Developer Profile
89 plugins · 15K total installs
How We Detect LH Posse
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
usyndicationu-syndication