
Plain Text Custom Post Type Security & Risk Analysis
wordpress.org/plugins/plain-text-custom-post-typeAdds a custom post type for plain text files that can be used for JavaScript or CSS.
Is Plain Text Custom Post Type Safe to Use in 2026?
Generally Safe
Score 85/100Plain Text Custom Post Type has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'plain-text-custom-post-type' plugin, version 0.2, exhibits a remarkably clean static analysis report, indicating a strong adherence to secure coding practices. The absence of any detected dangerous functions, unsanitized taint flows, or SQL queries not using prepared statements is highly commendable. Furthermore, the complete lack of file operations, external HTTP requests, and the presence of 100% properly escaped output signals a robust defense against common web vulnerabilities. The plugin also demonstrates a minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited.
Adding to this positive assessment is the plugin's vulnerability history, which is entirely clear. The absence of any known CVEs, past or present, suggests a well-maintained codebase that has not been a target or source of security issues. This history, combined with the static analysis findings, points to a plugin that is currently very secure.
While the current state of this plugin is excellent, it's important to acknowledge that even well-written code can have undiscovered vulnerabilities. The lack of any detected issues, particularly in taint analysis, might also be attributed to a very limited code complexity or functionality. However, based on the provided data, 'plain-text-custom-post-type' v0.2 presents a low-risk profile. The primary strength lies in its proactive secure coding and zero-incident history.
Plain Text Custom Post Type Security Vulnerabilities
Plain Text Custom Post Type Release Timeline
Plain Text Custom Post Type Code Analysis
Plain Text Custom Post Type Attack Surface
WordPress Hooks 14
Maintenance & Trust
Plain Text Custom Post Type Maintenance & Trust
Maintenance Signals
Community Trust
Plain Text Custom Post Type Alternatives
Raw HTML
raw-html
Lets you use raw HTML or any other code in your posts. You can also disable smart quotes and other automatic formatting on a per-post basis.
Custom CSS and JS
custom-css-and-js
Custom CSS and JavaScript allows you to add custom internal and external CSS and JavaScripts to individual posts.
Insert JavaScript and CSS
insert-javascript-css
Adds fields to the post and page edit pages that allow you to insert custom JavaScript or CSS for that post or page.
Specific CSS/JS for Posts and Pages
specific-cssjs-for-posts-and-pages
With Specific CSS/JS for Posts and Pages you can add CSS or JavaScript files to a specific page or post.
Custom JS
custom-js
Custom JS is easy to use. Custom JS WordPress plugin allows you to Custom JS fields in your theme - include js in head or footer.
Plain Text Custom Post Type Developer Profile
4 plugins · 430 total installs
How We Detect Plain Text Custom Post Type
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plain-text-custom-post-type/jquery.textarea.js/wp-content/plugins/plain-text-custom-post-type/jquery.textarea.jsHTML / DOM Fingerprints
name="plain_text_cpt_content_type"name="plain_text_insert"jQuery