
Neuron Expert Security & Risk Analysis
wordpress.org/plugins/neuron-postsThis plugin relies on the Neuron Expert API service. A Neuron Expert WordPress plugin to display user posts and more.
Is Neuron Expert Safe to Use in 2026?
Generally Safe
Score 92/100Neuron Expert has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "neuron-posts" plugin version 1.0.9.30 exhibits a mixed security posture. On the positive side, the absence of known CVEs and a clean vulnerability history are strong indicators of responsible development and maintenance. The code also demonstrates good practices by using prepared statements for all SQL queries, indicating a low risk of SQL injection vulnerabilities. Additionally, there are no direct file operations or dangerous function calls identified, further bolstering its security profile.
However, several areas raise concerns. The plugin's attack surface consists solely of 5 shortcodes, and while the static analysis reports 0 unprotected entry points, it's crucial to verify that these shortcodes are robustly secured against potential abuse. The taint analysis revealing 4 flows with unsanitized paths, even without critical or high severity, warrants investigation. These flows, coupled with a notable 37% of output not being properly escaped (67 total outputs, 63% properly escaped), suggest potential risks for Cross-Site Scripting (XSS) or data leakage if user-supplied data is involved in these unsanitized paths or unescaped outputs. The lack of any nonce checks or capability checks on the identified entry points is a significant weakness, leaving them potentially vulnerable to various attacks if they process user input.
In conclusion, while the "neuron-posts" plugin benefits from a clean vulnerability history and good SQL handling, the presence of unsanitized taint flows, a substantial amount of unescaped output, and a complete absence of nonce and capability checks on its entry points introduce tangible security risks that require attention and mitigation. The overall security is moderate, with clear areas for improvement to reach a more robust state.
Key Concerns
- Unsanitized taint flows found
- Significant unescaped output detected
- No nonce checks on entry points
- No capability checks on entry points
Neuron Expert Security Vulnerabilities
Neuron Expert Code Analysis
Output Escaping
Data Flow Analysis
Neuron Expert Attack Surface
Shortcodes 5
WordPress Hooks 12
Maintenance & Trust
Neuron Expert Maintenance & Trust
Maintenance Signals
Community Trust
Neuron Expert Alternatives
REST API Post Embeds
rest-api-post-embeds
Embed posts from your site or others' into your posts and pages.
Display Post Feed from Medium
display-post-feed-from-medium
Display Post Feed from Medium is a WordPress plugin to display the posts/articles from medium.com on any page/post via the shortcode.
Init View Count – AI-Powered, Trending, REST API
init-view-count
Count post views accurately via REST API with customizable display. Lightweight, fast, and extensible. Includes shortcode with multiple layouts.
IA Escritora Connector
ia-escritora-connector
Este plugin permite conexões seguras com a API IA Escritora para criação automatizada de posts.
WP REST API – Filter posts date wise using given column
wp-rest-api-filter-posts-date-wise-using-given-column
In WordPress 4.7, Posts cannot be filtered based on modified, modified_gmt, date_gmt fields.
Neuron Expert Developer Profile
1 plugin · 10 total installs
How We Detect Neuron Expert
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/neuron-posts/template/neuron-news-card.phpHTML / DOM Fingerprints
neuron-paginationneuron-posts-row<div class="neuron-pagination" style="text-align: center; margin-top: 20px;"><div class="tabs__content"><div class="neuron-posts-row" style="display: flex; gap: 20px;">