
List Media Security & Risk Analysis
wordpress.org/plugins/list-mediaThis plugin allows you to list all (or part) of your medias on custom Page / Post.
Is List Media Safe to Use in 2026?
Generally Safe
Score 85/100List Media has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "list-media" v1.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, SQL queries executed via prepared statements, file operations, and external HTTP requests are all indicators of good development practices. Furthermore, the lack of recorded vulnerabilities in its history suggests a stable and potentially well-maintained codebase.
However, significant concerns arise from the output escaping and nonce check findings. The fact that 100% of the observed outputs are not properly escaped presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities, especially given that the plugin has at least one shortcode which is a common entry point for user-generated content to be displayed.
While the attack surface is small and there are no immediate indications of critical taint flows or unauthenticated entry points, the unescaped output is a critical weakness that could be exploited. The absence of nonce checks, while not directly tied to an authenticated entry point in this specific analysis, is a general security best practice that is missing. The overall security is compromised by these oversight.
In conclusion, "list-media" v1.0 demonstrates strengths in avoiding common pitfalls like raw SQL and dangerous functions. However, the critical flaw in output escaping and the missing nonce checks significantly weaken its security, making it vulnerable to XSS attacks if user-supplied data is processed and displayed without proper sanitization. The absence of historical vulnerabilities is a good sign, but it does not negate the current risks identified in the code.
Key Concerns
- Unescaped output detected
- Missing nonce checks
List Media Security Vulnerabilities
List Media Release Timeline
List Media Code Analysis
Output Escaping
List Media Attack Surface
Shortcodes 1
Maintenance & Trust
List Media Maintenance & Trust
Maintenance Signals
Community Trust
List Media Alternatives
Custom Post Type Lister – CPT Lister
custom-post-type-lister-cpt-lister
This plugin allows you to list a custom post type in your posts / pages with one simple shortcode.
Etsy Shop
etsy-shop
Plugin that allow you to insert Etsy Shop sections in pages or posts using the bracket/shortcode method.
Popular Brand Icons – Simple Icons
simple-icons
An easy to use lightweight SVG icons plugin with over 1500+ brand icons. Use these icons in your menus, widgets, posts, or pages.
W4 Post List
w4-post-list
W4 Post List lets you create a list of posts, terms, users or a combined one. Decorate output using shortcodes. It's just easy and fun.
Webcomic
webcomic
Comic publishing power for the web. Turn your WordPress-powered site into a comic publishing platform with Webcomic.
List Media Developer Profile
10 plugins · 220 total installs
How We Detect List Media
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
list-media-tablelist_mediaheaderattachmenttitleauthoruploaded-todate<table class='list_media'><th class='header'>File</th><img src='<a href='