list-posts WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/list-posts

This is a a plugin that lists the latest posts on any page (or post). It does not use an iframe. It is extremely simple, and honors permissions and pa …

30 active installs v1.1.1 PHP + WP 2.6+ Updated Dec 22, 2010
combined-pageeditable-archive-pagelatest-newslist-posts
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is list-posts WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

list-posts WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'list-posts' v1.1.1 plugin exhibits a strong security posture with no identified vulnerabilities or concerning code signals. The absence of dangerous functions, proper use of prepared statements for SQL, and 100% output escaping are excellent security practices. Furthermore, the lack of any attack surface points like AJAX handlers, REST API routes, or shortcodes significantly reduces the potential for external exploitation. The plugin also has no recorded vulnerability history, indicating a stable and secure development track record.

While the analysis shows a very clean codebase, the most notable observation is the complete lack of entry points (AJAX, REST API, shortcodes, cron events) and consequently, no capability or nonce checks are required or present. This can be interpreted in two ways: either the plugin's functionality is extremely limited and doesn't require any user interaction points, or there's a potential for future expansion that might introduce security risks if not handled with care. However, as it stands, there are no immediate security concerns with this version.

Vulnerabilities
None known

list-posts WordPress Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

list-posts WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Attack Surface

list-posts WordPress Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterthe_contentlist-posts.php:372
Maintenance & Trust

list-posts WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedDec 22, 2010
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

list-posts WordPress Plugin Developer Profile

BMLTGuy

2 plugins · 130 total installs

94
trust score
Avg Security Score
92/100
Avg Patch Time
4 days
View full developer profile
Detection Fingerprints

How We Detect list-posts WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/list-posts/list-posts.js
Script Paths
/wp-content/plugins/list-posts/list-posts.js
Version Parameters
list-posts/list-posts.js?ver=

HTML / DOM Fingerprints

CSS Classes
listposts_cat_link
Shortcode Output
<form action="method="post"><label for="type="password"
FAQ

Frequently Asked Questions about list-posts WordPress Plugin