Query Loop Masonry Lite Security & Risk Analysis

wordpress.org/plugins/ph-queryloop-masonry-lite

Add beautiful masonry layouts to WordPress Query Loop blocks. Pinterest-style grids with no vendor lock-in.

0 active installs v1.0.0 PHP 8.0+ WP 6.7+ Updated Jan 12, 2026
gridgutenberglayoutmasonryquery-loop
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Query Loop Masonry Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Query Loop Masonry Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'ph-queryloop-masonry-lite' v1.0.0 plugin exhibits an excellent security posture. The static analysis reveals a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Crucially, there are no unprotected entry points detected. The code further demonstrates good practices by avoiding dangerous functions, exclusively using prepared statements for SQL queries, and properly escaping all identified output. No file operations or external HTTP requests are present, and notably, there are no detected nonce checks or capability checks. The absence of any taint analysis findings, critical or high severity, further reinforces its secure design.

The vulnerability history is equally clean, with zero known CVEs, unpatched vulnerabilities, or recorded common vulnerability types. This lack of historical issues suggests a commitment to security by the developers or a lack of past issues being publicly disclosed. While the absence of capability checks might be a concern in a more complex plugin, in this case, with zero entry points, it poses no immediate risk. The plugin's strengths lie in its minimal attack surface and the absence of common vulnerability patterns in its code. The primary weakness, if it can be called that, is the complete lack of capability checks and nonce checks, which, while not an issue with the current zero entry points, could become a vulnerability if new entry points are added in future versions without proper security considerations.

Vulnerabilities
None known

Query Loop Masonry Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Query Loop Masonry Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Query Loop Masonry Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionenqueue_block_editor_assetsph-queryloop-masonry-lite.php:84
actionenqueue_block_assetsph-queryloop-masonry-lite.php:85
filterrender_block_dataph-queryloop-masonry-lite.php:86
filterplugin_row_metaph-queryloop-masonry-lite.php:87
Maintenance & Trust

Query Loop Masonry Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 12, 2026
PHP min version8.0
Downloads111

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Query Loop Masonry Lite Developer Profile

Adam Husar / Pixel Hero

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Query Loop Masonry Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ph-queryloop-masonry-lite/build/js/edit.js/wp-content/plugins/ph-queryloop-masonry-lite/build/css/edit.css/wp-content/plugins/ph-queryloop-masonry-lite/build/js/screen.js/wp-content/plugins/ph-queryloop-masonry-lite/build/css/screen.css
Script Paths
/wp-content/plugins/ph-queryloop-masonry-lite/build/js/edit.js/wp-content/plugins/ph-queryloop-masonry-lite/build/js/screen.js
Version Parameters
ph-queryloop-masonry-lite/build/js/edit.js?ver=ph-queryloop-masonry-lite/build/css/edit.css?ver=ph-queryloop-masonry-lite/build/js/screen.js?ver=ph-queryloop-masonry-lite/build/css/screen.css?ver=

HTML / DOM Fingerprints

CSS Classes
ph-ql-masonry
Data Attributes
phQlMasonry
FAQ

Frequently Asked Questions about Query Loop Masonry Lite