
Post Connector Security & Risk Analysis
wordpress.org/plugins/post-connectorA WordPress plugin that allows you to easily create related posts that don't lag your server!
Is Post Connector Safe to Use in 2026?
Use With Caution
Score 59/100Post Connector has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'post-connector' plugin v1.0.11 exhibits a mixed security posture. While it demonstrates good practices in SQL query handling, nonce checks, and capability checks, indicating some awareness of security principles, several areas raise concerns. The static analysis reveals a significant portion of output is not properly escaped (39% escaped), which, when combined with taint analysis showing unsanitized paths, presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Although no critical or high-severity taint flows were found, the presence of unsanitized paths is a red flag. The vulnerability history is particularly worrying, with four known CVEs, one of which remains unpatched, and all historically being of medium severity and related to XSS. This pattern suggests a recurring weakness in input sanitization and output escaping, despite some efforts in the current version. The plugin's strengths lie in its controlled attack surface and secure database interactions, but the ongoing XSS issues and unpatched vulnerability significantly detract from its overall security. A more robust approach to output sanitization and prompt patching of known vulnerabilities are essential for improving its security.
Key Concerns
- Output escaping is insufficient (39% escaped)
- Taint analysis shows unsanitized paths
- 1 unpatched CVE (medium severity)
- Bundled library (TinyMCE) potential risk
Post Connector Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Post Connector <= 1.0.11 - Reflected Cross-Site Scripting
Post Connector <= 1.0.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
Post Connector < 1.0.4 - Reflected Cross-Site Scripting
Post Connector <= 1.0.3 and Post Conector Premium <= 1.6.3 - Reflected Cross-Site Scripting
Post Connector Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Post Connector Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Post Connector Maintenance & Trust
Maintenance Signals
Community Trust
Post Connector Alternatives
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Contextual Related Posts
contextual-related-posts
Keep visitors on your site longer with intelligent, fast-loading, contextually related posts. Block, shortcode, custom post type and widget ready.
Related Posts for WordPress
related-posts-for-wp
The best WordPress plugin for related posts. Simple, flexible, powerful algorithm, and built-in caching. Fully setup with only 1 click!
Post Connector Developer Profile
8 plugins · 62K total installs
How We Detect Post Connector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-connector/core/assets/js/post-connector-ptl.min.js/wp-content/plugins/post-connector/core/assets/js/post-connector-ptl.js/wp-content/plugins/post-connector/core/assets/js/post-connector-connection-edit.min.js/wp-content/plugins/post-connector/core/assets/js/post-connector-connection-edit.js/wp-content/plugins/post-connector/core/assets/js/post-connector-pl.min.js/wp-content/plugins/post-connector/core/assets/js/post-connector-pl.js/wp-content/plugins/post-connector/core/assets/js/post-connector-widget-shortcode.min.js/wp-content/plugins/post-connector/core/assets/js/post-connector-widget-shortcode.js+2 morecore/assets/js/post-connector-ptlcore/assets/js/post-connector-connection-editcore/assets/js/post-connector-plcore/assets/js/post-connector-widget-shortcodepost-connector/core/assets/js/post-connector-ptl.min.js?ver=post-connector/core/assets/js/post-connector-ptl.js?ver=post-connector/core/assets/js/post-connector-connection-edit.min.js?ver=post-connector/core/assets/js/post-connector-connection-edit.js?ver=post-connector/core/assets/js/post-connector-pl.min.js?ver=post-connector/core/assets/js/post-connector-pl.js?ver=post-connector/core/assets/js/post-connector-widget-shortcode.min.js?ver=post-connector/core/assets/js/post-connector-widget-shortcode.js?ver=post-connector/core/assets/css/post-connector.min.css?ver=post-connector/core/assets/css/post-connector.css?ver=HTML / DOM Fingerprints
sp_js[post_connector_[subposts_show_childs]