
Post List Designer – Category Post, Recent Post, Post List Security & Risk Analysis
wordpress.org/plugins/post-list-designerDisplay WordPress Post on your website in a List or Archive list view. Display category post, archive post, recent post and post list with category.
Is Post List Designer – Category Post, Recent Post, Post List Safe to Use in 2026?
Generally Safe
Score 99/100Post List Designer – Category Post, Recent Post, Post List has a strong security track record. Known vulnerabilities have been patched promptly.
The 'post-list-designer' v3.4.2 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a clean bill of health regarding dangerous functions, SQL injection risks, file operations, and external HTTP requests. Notably, all SQL queries are prepared, and a high percentage of output is properly escaped, indicating good development practices in these areas. The total attack surface is relatively small, and there are no immediate entry points identified as unprotected.
However, several concerning aspects warrant attention. The plugin has a history of two medium-severity Cross-Site Scripting (XSS) vulnerabilities, with the last one being relatively recent. The absence of any nonce checks and capability checks in the provided static analysis data is a significant concern, as these are fundamental security mechanisms for preventing CSRF and unauthorized access, especially for shortcodes which represent a direct entry point into the plugin's functionality. While the taint analysis shows no immediate issues, the historical XSS vulnerabilities combined with the lack of nonces and capability checks suggest a potential for exploitation if malicious input is not handled rigorously within the shortcode processing.
In conclusion, while 'post-list-designer' v3.4.2 demonstrates good practices in areas like SQL handling and output escaping, the lack of fundamental security checks (nonces, capabilities) and its history of XSS vulnerabilities are significant weaknesses. The presence of these historical issues, even if currently patched, indicates a recurring pattern that necessitates caution and vigilance. The plugin's strengths are overshadowed by these critical omissions in its security implementation.
Key Concerns
- History of 2 medium XSS vulnerabilities
- 0 Nonce checks present
- 0 Capability checks present
- Bundled Freemius v1.0 library
- 16% of outputs not properly escaped
Post List Designer – Category Post, Recent Post, Post List Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Posts List Designer by Category – List Category Posts Or Recent Posts <= 3.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Posts List Designer by Category <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scriptiong via Shortcode
Post List Designer – Category Post, Recent Post, Post List Code Analysis
Bundled Libraries
Output Escaping
Post List Designer – Category Post, Recent Post, Post List Attack Surface
Shortcodes 3
WordPress Hooks 6
Maintenance & Trust
Post List Designer – Category Post, Recent Post, Post List Maintenance & Trust
Maintenance Signals
Community Trust
Post List Designer – Category Post, Recent Post, Post List Alternatives
Display Posts As List, Grid, Thumbs
ultimate-content-views
This plugin lets you list posts by category, author, tags, and more, using a shortcode on posts, pages, or widgets with plenty of customization option …
Recent Posts by Tags
recent-posts-by-tags
This plugin creates a widget with a list of recent posts belonging to selected tags
Bake Posts
bake-posts
Bake Post can be used to display recent posts and posts from particular category and tags. (Not compatible for Multisites)
Recent Post Scroll Widget
qsd-owl-slider
Recent Post Scroll Widget is very customizable post widget . There are a lot's of option to display your recent post
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
Post List Designer – Category Post, Recent Post, Post List Developer Profile
3 plugins · 36K total installs
How We Detect Post List Designer – Category Post, Recent Post, Post List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-list-designer/assets/css/fs-pricing.css/wp-content/plugins/post-list-designer/assets/css/bld-public.csspost-list-designer/assets/css/fs-pricing.css?ver=post-list-designer/assets/css/bld-public.css?ver=HTML / DOM Fingerprints
pld-archive-list-containerdata-post-list-designer[pld_archive_list][pld_simple_list][pld_post_list]