
Post Display Security & Risk Analysis
wordpress.org/plugins/post-displayPlugin Display Post with multiple layouts order by date, title, random... Developer can override HTML or create new layout in their theme.
Is Post Display Safe to Use in 2026?
Generally Safe
Score 85/100Post Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'post-display' plugin v1.0.0 exhibits a generally good security posture, particularly in its handling of entry points. All identified AJAX handlers and REST API routes appear to have authentication checks, and there are no unauthenticated REST API routes. The plugin also demonstrates a commitment to secure coding practices with a high percentage of SQL queries using prepared statements and a significant number of nonce checks. The absence of any recorded vulnerabilities in its history is a positive indicator of its current stability and the development team's attention to security.
However, there are notable areas for improvement. The presence of 8 instances of the 'unserialize' function is a significant concern, as it can be a vector for remote code execution if untrusted data is unserialized. Furthermore, only 32% of output is properly escaped, leaving room for potential Cross-Site Scripting (XSS) vulnerabilities. While taint analysis found no unsanitized flows, the presence of 'unserialize' and insufficient output escaping warrants careful scrutiny.
In conclusion, while the plugin has strengths in its protected entry points and secure SQL query practices, the potential risks associated with 'unserialize' and the low output escaping rate are critical weaknesses that should be addressed to ensure a robust security profile. The clean vulnerability history is encouraging but does not negate the inherent risks in the identified code signals.
Key Concerns
- Dangerous function 'unserialize' used
- Low percentage of properly escaped output
Post Display Security Vulnerabilities
Post Display Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Post Display Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Post Display Maintenance & Trust
Maintenance Signals
Community Trust
Post Display Alternatives
Web Fonts
web-fonts
Start using web fonts on your site today! Support for web fonts from Fonts.com and Google Web Fonts is included.
Wp Post Views Counter
wp-post-views-counter
Used to post views for a single post type in wordpress it collects both unique and all returning visits for a single post as a post meta .
CW Show on Selected Pages
cw-show-on-selected-pages-sosp
Have you ever tried to display sidebar-content just on selected pages? You can realize this with this widget. You can choose wether you want to displa …
Post Views by DevDesignDazzle
devdesigndazzle-post-views
Post Views tracks WordPress views with bot filtering, stats, and top posts displays. Customize easily and boost your site!
ShowCaseGlut
showcaseglut
ShowCaseGlut Plugin for WordPress helps you create beautiful Tabs and Accordions on your website with custom post types and flexible shortcodes.
Post Display Developer Profile
7 plugins · 1K total installs
How We Detect Post Display
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-display/tzpost-style.css/wp-content/plugins/post-display/js/tzpost.frnt.script.js/wp-content/plugins/post-display/js/tzpost.script.js/wp-content/plugins/post-display/css/tzcustom_display_admin.css/wp-content/plugins/post-display/js/tzpost.frnt.script.js/wp-content/plugins/post-display/js/tzpost.script.jsHTML / DOM Fingerprints
name="tzpost_category[]"name="tzpost-js-script"data-tzpost-ajax-noncetzpostajx