Post As Subdomain Lite Security & Risk Analysis

wordpress.org/plugins/post-as-subdomain-free

Convert post into Subdomain.

40 active installs v2.5.0 PHP + WP 3.0.1+ Updated Dec 17, 2025
postpostsseosubdomain
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post As Subdomain Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Post As Subdomain Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'post-as-subdomain-free' v2.5.0 plugin exhibits a generally strong security posture, with no identified vulnerabilities in its history and a limited attack surface. The absence of AJAX handlers, REST API routes, shortcodes, and cron events without authentication checks is commendable. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and performing at least one nonce and capability check. The lack of critical or high severity taint analysis results further reinforces this positive assessment.

However, a significant concern arises from the low percentage of properly escaped output. With only 13% of the 8 total outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through user-supplied data that is not adequately sanitized before being displayed to other users. While the plugin has no recorded vulnerability history, this oversight in output escaping is a critical weakness that could be exploited. The single external HTTP request, while not inherently dangerous, warrants careful monitoring if its destination or purpose is not clearly understood and secured.

In conclusion, the plugin's strengths lie in its minimal attack surface and secure handling of database operations. The absence of known vulnerabilities is a positive indicator. However, the low rate of output escaping presents a clear and present danger for XSS attacks. This weakness needs to be addressed promptly to mitigate potential security risks.

Key Concerns

  • Low output escaping rate (13%)
Vulnerabilities
None known

Post As Subdomain Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Post As Subdomain Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
1 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

13% escaped8 total outputs
Attack Surface

Post As Subdomain Lite Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterplugin_row_metapost.php:19
actionadmin_menupost.php:43
actioninitpost.php:455
filterpost_rewrite_rulespost.php:463
filterpost_linkpost.php:464
Maintenance & Trust

Post As Subdomain Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 17, 2025
PHP min version
Downloads4K

Community Trust

Rating68/100
Number of ratings5
Active installs40
Developer Profile

Post As Subdomain Lite Developer Profile

M. Ali Saleem

6 plugins · 690 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post As Subdomain Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
postassubdomain-headerpostassubdomain-containerpostassubdomain-mainpostcardpostcard-headerpostassubdomain-formform-groupform-label+15 more
Data Attributes
name="spost[]"id="post-select"name="spost[]"id="post-select"name="spost[]"id="post-select"+2 more
FAQ

Frequently Asked Questions about Post As Subdomain Lite