Post Scriptum Security & Risk Analysis

wordpress.org/plugins/post-scriptum

A simple plugin adding optional per-category and per-tag text/HTML at the end of the post content.

10 active installs v1.0 PHP + WP 2.0+ Updated Jul 1, 2009
categorycontentposttag
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Scriptum Safe to Use in 2026?

Generally Safe

Score 85/100

Post Scriptum has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "post-scriptum" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points, dangerous functions, direct SQL queries, unescaped output, file operations, external requests, or nonce/capability checks is highly commendable and suggests diligent secure coding practices. Furthermore, the plugin has no known vulnerability history, indicating a consistent track record of security. This lack of identified weaknesses in both static analysis and historical data points to a well-secured plugin.

While the current analysis shows no immediate threats, it's important to acknowledge that the absence of findings could also be due to the limited scope of the static analysis or the plugin's functionality. For instance, the lack of analyzed taint flows might mean the plugin simply doesn't process user-supplied data in a way that would typically trigger such findings. However, given the comprehensive '0' counts across all critical security indicators, the plugin appears to be robustly developed from a security perspective for its current version and functionality.

Vulnerabilities
None known

Post Scriptum Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Post Scriptum Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Post Scriptum Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtercategory_descriptionpost-scriptum.php:52
filterterm_descriptionpost-scriptum.php:53
filterthe_contentpost-scriptum.php:54
Maintenance & Trust

Post Scriptum Maintenance & Trust

Maintenance Signals

WordPress version tested2.8
Last updatedJul 1, 2009
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Post Scriptum Developer Profile

mortenf

4 plugins · 110 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Scriptum

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
post-scriptumpost-scriptum-category-post-scriptum-tag-
Shortcode Output
<div class="post-scriptum">
FAQ

Frequently Asked Questions about Post Scriptum