
Mindvalley Include Post Content Security & Risk Analysis
wordpress.org/plugins/mindvalley-include-contentCreates shortcode [mv_include] to include content from another post/page.
Is Mindvalley Include Post Content Safe to Use in 2026?
Generally Safe
Score 85/100Mindvalley Include Post Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mindvalley-include-content" plugin v1.3.2 exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history is a significant strength, suggesting the developers have a track record of producing secure code. The plugin also demonstrates good practices in SQL query handling by exclusively using prepared statements, and it avoids file operations and external HTTP requests, which are common vectors for vulnerabilities.
However, a critical concern arises from the "Output escaping" signal, indicating that 100% of its outputs are not properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic content displayed by the plugin, if not rigorously sanitized by the calling code or if user-supplied data is directly reflected, could be exploited. The presence of a single shortcode as the sole entry point, while small, means any XSS vulnerability within this shortcode's output handling would be directly accessible.
While the plugin has a limited attack surface and no critical taint flows were detected, the complete lack of output escaping is a glaring weakness that overshadows other positive aspects. The vulnerability history is promising, but it cannot negate the immediate risk posed by unescaped output. Developers should prioritize addressing the output escaping issue to mitigate potential XSS attacks.
Key Concerns
- All outputs are unescaped
- Missing nonce checks on entry points
Mindvalley Include Post Content Security Vulnerabilities
Mindvalley Include Post Content Code Analysis
SQL Query Safety
Output Escaping
Mindvalley Include Post Content Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Mindvalley Include Post Content Maintenance & Trust
Maintenance Signals
Community Trust
Mindvalley Include Post Content Alternatives
Post/Page Import Export – Migrate Content with Custom Fields & Taxonomies
postpage-import-export-with-custom-fields-taxonomies
Export and import WordPress posts & pages as JSON files with full support for custom fields, taxonomies, ACF fields, and featured images.
Easy Content Adder
easy-content-adder
A WordPress plugin to easily add custom content to all of your Pages, Posts, and Custom Post Types.
WP Order By
wp-order-by
Simple and easy way to order your posts, pages or any other custom post-type in a various options.
WP Advanced Include
wp-advanced-include
Easily include WordPress Post / Page content with in another WordPress post/page using a simple shortcode. WP Advanced Include can include post conte …
Multiple Content Types
multiple-content-types
Easily select which content types (custom post types) you want to display on your main blog and archive pages.
Mindvalley Include Post Content Developer Profile
7 plugins · 160 total installs
How We Detect Mindvalley Include Post Content
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mindvalley-include-content/jquery.tooltip.min.js/wp-content/plugins/mindvalley-include-content/jquery.tooltip.css/wp-content/plugins/mindvalley-include-content/jquery.tooltip.min.jsHTML / DOM Fingerprints
mv_includeeditinforevjQuery[mv_include id='[mv_include slug='[mv_include path='