Custom Front Page Security & Risk Analysis

wordpress.org/plugins/mpress-custom-front-page

Easily set any page or post, including custom post types, as the homepage for your site.

1K active installs v1.1.2 PHP 5.3+ WP 3.0+ Updated Dec 13, 2020
custom-front-pagecustom-homepagecustom-post-typefront-pagehomepage
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom Front Page Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Front Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "mpress-custom-front-page" plugin v1.1.2 exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, cron events, dangerous functions, direct SQL queries, file operations, external HTTP requests, or taint flows is highly commendable. Furthermore, the plugin demonstrates good development practices with 100% of SQL queries using prepared statements and 100% of outputs being properly escaped. The lack of any recorded vulnerabilities, CVEs, or common vulnerability types in its history further reinforces its secure standing. This indicates a plugin developed with security as a primary concern, with a minimal attack surface and robust coding standards applied. The main area of concern, albeit minor given the overall analysis, is the complete absence of nonce and capability checks. While there are no entry points detected in this version, any future additions or modifications to the plugin that introduce such entry points without proper authentication and authorization checks would introduce significant security risks. As it stands, this version appears very secure.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

Custom Front Page Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Front Page Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Custom Front Page Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterwp_dropdown_pagesmpress-custom-front-page.php:55
actionpre_get_postsmpress-custom-front-page.php:57
actiontemplate_redirectmpress-custom-front-page.php:58
Maintenance & Trust

Custom Front Page Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedDec 13, 2020
PHP min version5.3
Downloads26K

Community Trust

Rating88/100
Number of ratings7
Active installs1K
Developer Profile

Custom Front Page Developer Profile

Micah Wood

8 plugins · 12K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Front Page

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Custom Front Page