
Post Preview Card Security & Risk Analysis
wordpress.org/plugins/post-preview-cardPost Preview Card is a Plugin that adds 3 beatiful widgets which previews posts in card shape. Made to be used with Elementor, Beaver or SiteOrigin pa …
Is Post Preview Card Safe to Use in 2026?
Generally Safe
Score 85/100Post Preview Card has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'post-preview-card' plugin version 2.0.3 exhibits a generally good security posture based on the provided static analysis. The absence of any entry points like AJAX handlers, REST API routes, or shortcodes significantly limits the potential attack surface. Furthermore, the code demonstrates strong practices by using prepared statements for all SQL queries and a high percentage of properly escaped output. The lack of dangerous functions, file operations, external HTTP requests, and the absence of vulnerability history also contribute to a positive security assessment. However, the static analysis does highlight two flows with unsanitized paths, which, while not classified as critical or high severity in the taint analysis, warrants attention as it indicates potential areas for injection vulnerabilities if the input data is not handled with sufficient sanitization in specific contexts. The complete absence of nonce and capability checks across all components, though currently not exploitable due to the limited attack surface, represents a potential weakness that could become a risk if new entry points are introduced in future versions without proper authentication and authorization mechanisms.
Key Concerns
- Flows with unsanitized paths
- No nonce checks
- No capability checks
Post Preview Card Security Vulnerabilities
Post Preview Card Release Timeline
Post Preview Card Code Analysis
Output Escaping
Data Flow Analysis
Post Preview Card Attack Surface
WordPress Hooks 10
Maintenance & Trust
Post Preview Card Maintenance & Trust
Maintenance Signals
Community Trust
Post Preview Card Alternatives
Init Embed Posts – Stylish, Fast, Portable
init-embed-posts
Embed WordPress posts or products anywhere – like a Twitter Card. No iframe. No oEmbed. Just pure JS, full control, and beautiful design.
Content Views – Post Grid & Filter, Recent Posts, Category Posts … (Shortcode, Gutenberg Blocks, and Widgets for Elementor)
content-views-query-and-display-post-page
Easy to show posts, pages, custom posts in customizable grid, list, slider, accordion... Available as Widgets (for Elementor), Shortcode, and Blocks.
Elementor Custom Skin
ele-custom-skin
Create new skins for Elementor PRO 3.x page builder. Design your own skins for Post and Post Archive Widgets using Elementor Loop Templates.
Public Post Preview
public-post-preview
Allow anonymous users to preview a draft of a post before it is published.
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid
the-post-grid
Display WordPress posts in beautiful grid, list, slider, and filter layouts. Works with Gutenberg, Elementor, Divi, and Shortcodes.
Post Preview Card Developer Profile
1 plugin · 10 total installs
How We Detect Post Preview Card
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-preview-card/public/css/bootstrap-btn.css/wp-content/plugins/post-preview-card/public/css/bootstrap-grid.css/wp-content/plugins/post-preview-card/public/css/bootstrap-card.css/wp-content/plugins/post-preview-card/public/css/peaw-original-layout.css/wp-content/plugins/post-preview-card/public/css/peaw-multiple-posts-style.css/wp-content/plugins/post-preview-card/public/js/multiple-posts-ajax-loader.jsHTML / DOM Fingerprints
peaw_multiple_postsdata-peaw-widget-multiple-posts-loaderpeaw_multiple_posts_ajax_loader