
List Posts with Pingbacks Security & Risk Analysis
wordpress.org/plugins/list-posts-with-pingbacks-trackbacksAdds a list of Posts with Pingbacks and Trackbacks to WordPress with a widget, shortcode, or theme functions.
Is List Posts with Pingbacks Safe to Use in 2026?
Generally Safe
Score 85/100List Posts with Pingbacks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "list-posts-with-pingbacks-trackbacks" v2017.08.13 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the lack of file operations or external HTTP requests are all positive indicators. Furthermore, the complete absence of known vulnerabilities (CVEs) in its history suggests a history of stable and secure development. However, there are areas that warrant caution. The code analysis reveals that 60% of output is properly escaped, meaning 40% of outputs are potentially unescaped. While the total number of outputs is low (5), this still presents a potential risk for Cross-Site Scripting (XSS) if any of these unescaped outputs are user-controllable. Additionally, the lack of nonce checks and capability checks on its single shortcode entry point is a significant concern. While there are no AJAX or REST API endpoints to analyze for these, the presence of a shortcode without proper authentication or authorization mechanisms could lead to unauthorized actions or information disclosure if the shortcode's functionality is sensitive. The taint analysis showing no flows is good, but the limited scope of the analysis (0 flows) means this doesn't provide complete assurance. Overall, the plugin is built on some good security foundations, but the unescaped output and lack of checks on the shortcode are notable weaknesses.
Key Concerns
- Unescaped output detected
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
List Posts with Pingbacks Security Vulnerabilities
List Posts with Pingbacks Code Analysis
Output Escaping
List Posts with Pingbacks Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
List Posts with Pingbacks Maintenance & Trust
Maintenance Signals
Community Trust
List Posts with Pingbacks Alternatives
Share on Mastodon
share-on-mastodon
Automatically share WordPress posts on Mastodon.
WP REST Yoast Meta
wp-rest-yoast-meta
Adds meta tags as generated by Yoast SEO to the WP REST API. And adds a custom endpoint to retrieve all redirects as they are set in Yoast SEO Premium …
Divi Title Module
mc-divi-title-module
This plugin adds a new module to the Divi builder, it allows to easily insert titles without going through the text module.
Share on Pixelfed
share-on-pixelfed
Automatically share WordPress (image) posts on Pixelfed.
Add Image to RSS Feed
add-image-to-rss-feed
** this plugin is no longer being update. Please feel free to adopt me! **
List Posts with Pingbacks Developer Profile
17 plugins · 130 total installs
How We Detect List Posts with Pingbacks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/list-posts-with-pingbacks-trackbacks/horshipsrectors-common.php/wp-content/plugins/list-posts-with-pingbacks-trackbacks/widgets/thissimyurl_ListPostsWithPingbacksTrackbacks_Widget.phpHTML / DOM Fingerprints
horshipsrectors-list-posts-with-pingbacks-trackbacksnofollow[horshipsrectors_list_posts_with_pingbacks_trackbacks]