Mass Pages/Posts Creator Security & Risk Analysis

wordpress.org/plugins/mass-pagesposts-creator

Mass Pages/Posts Creator is a plugin which provide a simplest interface by which user can create multiple Pages/Posts at a time.

1K active installs v2.2.1 PHP 5.6+ WP 5.0+ Updated Jan 12, 2026
amountbulkmassmultiplevolume
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 7, 2018
Safety Verdict

Is Mass Pages/Posts Creator Safe to Use in 2026?

Generally Safe

Score 99/100

Mass Pages/Posts Creator has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 7, 2018Updated 2mo ago
Risk Assessment

The "mass-pagesposts-creator" v2.2.1 plugin exhibits a generally good security posture with several positive indicators. The absence of critical or high severity taint flows, the exclusive use of prepared statements for SQL queries, and the presence of nonce checks are commendable. The static analysis also shows a lack of dangerous functions and file operations, further contributing to its security. However, there are areas that warrant attention. The fact that 19% of output is not properly escaped, while not a critical risk on its own, could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. Furthermore, the plugin has a history of a high severity vulnerability, specifically a missing authorization issue, which was last patched in 2018. While there are no currently unpatched CVEs, this past vulnerability suggests that authorization checks are an area that requires developer diligence.

Despite the clean slate in terms of current CVEs and taint analysis, the previous high-severity vulnerability linked to missing authorization is a significant concern and indicates a potential weakness in how access to certain functionalities is managed. The 19% of unescaped output is a moderate risk that should be addressed to prevent potential XSS attacks. The plugin's strengths lie in its secure handling of SQL and its use of nonce checks. The overall conclusion is that while the plugin has implemented many good security practices, the historical vulnerability and the unescaped output present remaining risks that need to be mitigated.

Key Concerns

  • High severity vulnerability in history
  • Unescaped output (19%)
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
1

Mass Pages/Posts Creator Security Vulnerabilities

CVEs by Year

1 CVE in 2018
2018
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2018-11580high · 7.3Missing Authorization

Mass Pages/Posts Creator <= 1.2.2 - Missing Authorization

Jun 7, 2018 Patched in 1.2.3 (2056d)
Code Analysis
Analyzed Mar 16, 2026

Mass Pages/Posts Creator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
39
169 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
2

Bundled Libraries

Select2Freemius1.0

Output Escaping

81% escaped208 total outputs
Attack Surface

Mass Pages/Posts Creator Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_mppc_plugin_setup_wizard_submitincludes\mass-pages-posts-creator-functions.php:362
authwp_ajax_page_finder_ajaxmass-pages-posts-creator.php:123
authwp_ajax_mpc_ajax_actionmass-pages-posts-creator.php:435
noprivwp_ajax_mpc_ajax_actionmass-pages-posts-creator.php:436
WordPress Hooks 15
filterhide_account_tabsincludes\mass-pages-posts-creator-functions.php:17
actionafter_account_detailsincludes\mass-pages-posts-creator-functions.php:35
actionhide_billing_and_payments_infoincludes\mass-pages-posts-creator-functions.php:47
actionhide_freemius_powered_byincludes\mass-pages-posts-creator-functions.php:59
filterplugin_row_metaincludes\mass-pages-posts-creator-functions.php:77
actionconnect/beforeincludes\mass-pages-posts-creator-functions.php:327
actionconnect/afterincludes\mass-pages-posts-creator-functions.php:344
actionadmin_initincludes\mass-pages-posts-creator-functions.php:405
actionadmin_enqueue_scriptsmass-pages-posts-creator.php:77
actionadmin_enqueue_scriptsmass-pages-posts-creator.php:78
filteradmin_footer_textmass-pages-posts-creator.php:79
actionadmin_initmass-pages-posts-creator.php:122
actionadmin_menumass-pages-posts-creator.php:472
actionadmin_headmass-pages-posts-creator.php:473
actionplugins_loadedmass-pages-posts-creator.php:479
Maintenance & Trust

Mass Pages/Posts Creator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 12, 2026
PHP min version5.6
Downloads71K

Community Trust

Rating84/100
Number of ratings17
Active installs1K
Developer Profile

Mass Pages/Posts Creator Developer Profile

dotsquares

37 plugins · 95K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
470 days
View full developer profile
Detection Fingerprints

How We Detect Mass Pages/Posts Creator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mass-pagesposts-creator/js/select2.min.js/wp-content/plugins/mass-pagesposts-creator/js/help-scout-beacon.js/wp-content/plugins/mass-pagesposts-creator/js/custom.js/wp-content/plugins/mass-pagesposts-creator/admin/css/select2.min.css/wp-content/plugins/mass-pagesposts-creator/admin/css/jquery-ui.min.css/wp-content/plugins/mass-pagesposts-creator/admin/css/jquery.timepicker.min.css
Script Paths
https://checkout.freemius.com/checkout.min.js
Version Parameters
mass-pages-posts-creator/js/select2.min.js?ver=mass-pages-posts-creator/js/help-scout-beacon.js?ver=mass-pages-posts-creator/js/custom.js?ver=mass-pages-posts-creator/admin/css/select2.min.css?ver=mass-pages-posts-creator/admin/css/jquery-ui.min.css?ver=mass-pages-posts-creator/admin/css/jquery.timepicker.min.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-mppc-option
JS Globals
adminajaxmppcp_fs
FAQ

Frequently Asked Questions about Mass Pages/Posts Creator