
Manage Custom Post Types Security & Risk Analysis
wordpress.org/plugins/manage-custom-post-typesThis plugin is use for Create a New Custom Post Types & also Enable/Disable the Custom post types.
Is Manage Custom Post Types Safe to Use in 2026?
Generally Safe
Score 85/100Manage Custom Post Types has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "manage-custom-post-types" v1.1 exhibits a strong overall security posture based on the provided static analysis and vulnerability history. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the lack of dangerous functions, file operations, and external HTTP requests are positive indicators of secure coding practices. The taint analysis showing no flows with unsanitized paths further reinforces this positive assessment.
However, there are several areas for concern. The fact that 100% of the SQL queries are not using prepared statements presents a significant risk of SQL injection vulnerabilities, especially given the presence of three SQL queries. While the plugin includes nonce checks, the complete absence of capability checks on any entry points means that even if nonces are implemented, unauthorized users might still be able to execute certain actions if they can discover or forge the nonces. The output escaping is also a concern, with only 27% of outputs being properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities.
The complete lack of any recorded CVEs, even historically, suggests a generally well-maintained and secure plugin. This, combined with the limited attack surface, provides a good foundation. However, the internal code analysis reveals potential weaknesses that, if exploited by an attacker who could bypass or bypass nonce checks, could lead to serious security incidents. The focus should be on addressing the SQL injection and XSS risks.
Key Concerns
- 100% of SQL queries not using prepared statements
- Only 27% of outputs properly escaped
- 0 capability checks on entry points
Manage Custom Post Types Security Vulnerabilities
Manage Custom Post Types Release Timeline
Manage Custom Post Types Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Manage Custom Post Types Attack Surface
WordPress Hooks 7
Maintenance & Trust
Manage Custom Post Types Maintenance & Trust
Maintenance Signals
Community Trust
Manage Custom Post Types Alternatives
Post Types Unlimited
post-types-unlimited
Create unlimited custom post types and custom taxonomies.
Custom post types, Custom Fields & more
custom-post-types
Custom Post Types, Custom Fields, Custom Taxonomies, Custom Templates, Custom Admin Pages, Custom Admin Notices. Directly from the WP dashboard.
Hierarchy
hierarchy
Move your Pages/Posts/Custom Post Type admin links from the sidebar to a Content menu that nests everything where it should be
Custom Post Types Bubbles
custom-post-types-bubbles
Easily add notifications bubble with counters in Post Types to display either pending or draft posts.
Genesis Custom Post Types Archives
genesis-custom-post-types-archives
Allows you to customize Genesis Custom Post Type archive pages for solid SEO.
Manage Custom Post Types Developer Profile
4 plugins · 50 total installs
How We Detect Manage Custom Post Types
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/manage-custom-post-types/admin/css/manage-custom-post-types-admin.css/wp-content/plugins/manage-custom-post-types/admin/js/manage-custom-post-types-admin.jsplugin_dir_url(__FILE__) . 'js/manage-custom-post-types-admin.js'manage-custom-post-types/admin/css/manage-custom-post-types-admin.css?ver=manage-custom-post-types/admin/js/manage-custom-post-types-admin.js?ver=HTML / DOM Fingerprints
mcpt_admin_menumcpt_statusmcpt_slugmcpt_namemcpt_icon