
ListPosts Shortcode Security & Risk Analysis
wordpress.org/plugins/listposts-shortcodeListPosts Shortcode is a shortcode that adds a highly customized list of blog posts anywhere on their site.
Is ListPosts Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100ListPosts Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The listposts-shortcode v1.2 plugin exhibits a generally poor security posture, despite the absence of known vulnerabilities and a limited attack surface. The most significant concern is the complete lack of output escaping and capability checks. With 9 output operations and no proper escaping, any data displayed via the shortcode is highly susceptible to Cross-Site Scripting (XSS) attacks. The presence of SQL queries without prepared statements is another critical risk, potentially leading to SQL injection vulnerabilities. While the plugin has no recorded vulnerability history and a small attack surface, these are not enough to mitigate the severe flaws identified in the code analysis. The lack of fundamental security practices like output sanitization and capability checks makes this plugin a high risk for any WordPress site.
Key Concerns
- Output escaping: 0% properly escaped
- SQL queries: 0% using prepared statements
- Nonce checks: 0
- Capability checks: 0
ListPosts Shortcode Security Vulnerabilities
ListPosts Shortcode Code Analysis
SQL Query Safety
Output Escaping
ListPosts Shortcode Attack Surface
Shortcodes 1
Maintenance & Trust
ListPosts Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
ListPosts Shortcode Alternatives
Recent Posts Easy
recent-posts-easy
A simple shortcode for displaying recent posts with thumbnails and meta descriptions.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Posts in Page
posts-in-page
Easily add one or more posts to any page using simple shortcodes.
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
ListPosts Shortcode Developer Profile
2 plugins · 40 total installs
How We Detect ListPosts Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
listpostslp-listposts-lilp-entrylp-entry-lp-imagelp-linkimagelp-text+5 moreclass="listposts-li clearfix"class="listposts-li lp-entry lp-entry-class="clearfix"class="block-link"class="lp-image"class="lp-linkimage"+7 more<ul class="listposts lp-<li class="listposts-li clearfix"><a class="block-link"<div class="lp-image">