Post Grid Free Security & Risk Analysis

wordpress.org/plugins/post-grid-free

Post Grid Free is a fully Responsive WordPress Plugin to display your WordPress post with different styles.

70 active installs v2.0.0 PHP + WP 4.0+ Updated Feb 4, 2026
gridpostpost-gird-shortcodepost-gridwordpress-post-grid
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Grid Free Safe to Use in 2026?

Generally Safe

Score 100/100

Post Grid Free has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "post-grid-free" v2.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history over time is a significant positive indicator. The code demonstrates good practices with the use of prepared statements for all SQL queries, proper nonce and capability checks, and no evident file operations or external HTTP requests. This suggests a development team that is mindful of security fundamentals.

However, a notable area of concern arises from the output escaping. With 272 total outputs, only 72% are properly escaped. This leaves a significant portion of outputs potentially vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is directly reflected without adequate sanitization. While the attack surface is small and all entry points appear to have authentication checks, the imperfect output escaping presents a tangible risk that could be exploited if an attacker can inject malicious scripts into data processed by the plugin.

In conclusion, while the plugin's development shows commendable security practices in many areas, the identified weakness in output escaping warrants attention. The lack of historical vulnerabilities is reassuring, but the current static analysis findings highlight a specific vulnerability that needs to be addressed to maintain a robust security profile.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Post Grid Free Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Post Grid Free Release Timeline

v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Post Grid Free Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
75
197 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

72% escaped272 total outputs
Attack Surface

Post Grid Free Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[picpostgirds] includes\shortcode\post-grid-free-shortcode.php:100
WordPress Hooks 9
actionadd_meta_boxesincludes\meta-boxes\post-grid-free-metaboxes.php:30
actionsave_postincludes\meta-boxes\post-grid-free-metaboxes.php:706
actioninitincludes\post-types\post-grid-free-post-type.php:56
filtermanage_picgridfree_posts_columnsincludes\post-types\post-grid-free-post-type.php:72
actionmanage_picgridfree_posts_custom_columnincludes\post-types\post-grid-free-post-type.php:82
filterwidget_textpost-grid-free.php:24
actionwp_enqueue_scriptspost-grid-free.php:35
actionplugins_loadedpost-grid-free.php:43
actionadmin_enqueue_scriptspost-grid-free.php:55
Maintenance & Trust

Post Grid Free Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 4, 2026
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Post Grid Free Developer Profile

pickelements

7 plugins · 610 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Grid Free

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/post-grid-free/public/css/font-awesome.css/wp-content/plugins/post-grid-free/public/css/post-grid-free-public.css/wp-content/plugins/post-grid-free/public/js/post-grid-free-public.js/wp-content/plugins/post-grid-free/admin/css/post-grid-free-admin.css/wp-content/plugins/post-grid-free/admin/js/post-grid-free-admin.js/wp-content/plugins/post-grid-free/admin/js/color-picker.js
Script Paths
/wp-content/plugins/post-grid-free/public/js/post-grid-free-public.js/wp-content/plugins/post-grid-free/admin/js/post-grid-free-admin.js/wp-content/plugins/post-grid-free/admin/js/color-picker.js

HTML / DOM Fingerprints

CSS Classes
pic-post-grid-free
Data Attributes
data-post-id
Shortcode Output
[picpostgirds id="
FAQ

Frequently Asked Questions about Post Grid Free