Listings Post Type Enable Security & Risk Analysis

wordpress.org/plugins/listings-post-type-enable

A simple plugin that creates a "listings" custom post type. It is also add a recent listings custom widget and a new category listings widge …

100 active installs v0.1.5 PHP + WP 3.0.1+ Updated Aug 1, 2022
custom-post-typecustom-widgetdirectory-post-typelistings-post-type
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Listings Post Type Enable Safe to Use in 2026?

Generally Safe

Score 85/100

Listings Post Type Enable has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "listings-post-type-enable" plugin, version 0.1.5, exhibits a generally positive security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events, particularly those lacking authentication or permission checks, significantly limits the plugin's attack surface. Furthermore, the analysis reveals no critical or high-severity taint flows, no dangerous function usage, and all SQL queries are properly prepared. The presence of nonce and capability checks, while only one of each, indicates an awareness of WordPress security best practices.

However, a notable concern lies within the output escaping. With only 32% of the 44 identified outputs being properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through user-supplied data that is not adequately sanitized before being displayed to users. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong positive. This, combined with the limited attack surface and secure handling of SQL, suggests a potentially well-maintained codebase. Nevertheless, the unescaped output is a substantial weakness that requires immediate attention to prevent potential exploitation.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Listings Post Type Enable Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Listings Post Type Enable Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
30
14 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

32% escaped44 total outputs
Attack Surface

Listings Post Type Enable Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitlistings.php:52
actioninitlistings.php:88
actioninitlistings.php:124
actionwidgets_initlistings.php:131
actionsave_postlistings.php:139
actiondeleted_postlistings.php:140
actionswitch_themelistings.php:141
actionadd_meta_boxeslistings.php:393
actionsave_postlistings.php:415
Maintenance & Trust

Listings Post Type Enable Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedAug 1, 2022
PHP min version
Downloads21K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Listings Post Type Enable Developer Profile

AyeCode

13 plugins · 3K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
124 days
View full developer profile
Detection Fingerprints

How We Detect Listings Post Type Enable

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
ketchupthemes-widget_recent_listings
FAQ

Frequently Asked Questions about Listings Post Type Enable