
Lightpost Security & Risk Analysis
wordpress.org/plugins/lightpostThis plugin allows churches to display content from their Lightpost account on their Wordpress-based website.
Is Lightpost Safe to Use in 2026?
Generally Safe
Score 85/100Lightpost has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'lightpost' plugin v1.1.4 exhibits a generally good security posture based on the provided static analysis. The absence of any identified CVEs and the clean vulnerability history suggest a history of secure development and maintenance. The plugin also demonstrates good practices by having a seemingly zero attack surface and utilizing prepared statements for all SQL queries, which are significant strengths. However, concerns arise from the output escaping, where only 52% of outputs are properly escaped, indicating a potential for cross-site scripting (XSS) vulnerabilities. The taint analysis also revealed 5 flows with unsanitized paths, which could be a vector for other security issues, though no critical or high severity issues were identified in this area. The plugin's reliance on external HTTP requests (6) also presents a potential risk if these external services are compromised or introduce vulnerabilities. While the plugin has a strong foundation, the unescaped outputs and unsanitized paths are areas that require attention to ensure a robust security profile.
Key Concerns
- Low percentage of properly escaped output
- Flows with unsanitized paths detected
- Presence of external HTTP requests
Lightpost Security Vulnerabilities
Lightpost Code Analysis
Output Escaping
Data Flow Analysis
Lightpost Attack Surface
WordPress Hooks 5
Maintenance & Trust
Lightpost Maintenance & Trust
Maintenance Signals
Community Trust
Lightpost Alternatives
Church Admin
church-admin
Organise and communicate church life, with associated Android and iOS app for your congregation.
Church Social
church-social
This plugin allows churches to display content from their Church Social account on their WordPress website.
Sugar Calendar – Events Calendar, Event Tickets, and Events Management Platform
sugar-calendar-lite
Easily manage events and sell tickets on your WordPress site. Sugar Calendar is easy-to-use, reliable, and exceptionally powerful. See for yourself.
EventON – Events Calendar
eventon-lite
Create beautiful, responsive event calendars with unlimited events, repeating schedules, virtual support, and a sleek minimal design!
Church Content – Sermons, Events and More
church-theme-content
Provides an interface for managing sermons, events, people and locations. A compatible theme is required for presenting content from these church-cent …
Lightpost Developer Profile
1 plugin · 0 total installs
How We Detect Lightpost
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lightpost/assets/css/lightpost.css/wp-content/plugins/lightpost/assets/js/lightpost.js/wp-content/plugins/lightpost/assets/js/lightpost.jslightpost/assets/css/lightpost.css?ver=lightpost/assets/js/lightpost.js?ver=HTML / DOM Fingerprints
lightpost-sermon-archivelightpost-bible-classlightpost-directorydata-lightpost-sermon-iddata-lightpost-bible-class-iddata-lightpost-directory-id[lightpost_sermons][lightpost_bible_classes][lightpost_directory]