
Post Snippets – Custom WordPress Code Snippets Customizer Security & Risk Analysis
wordpress.org/plugins/post-snippetsCreate WordPress custom snippets shortcodes and reusable content and insert them in into your posts and pages.
Is Post Snippets – Custom WordPress Code Snippets Customizer Safe to Use in 2026?
Generally Safe
Score 89/100Post Snippets – Custom WordPress Code Snippets Customizer has a strong security track record. Known vulnerabilities have been patched promptly.
The post-snippets v4.0.18 plugin exhibits a mixed security posture. While it demonstrates good practices in its use of prepared statements for SQL queries and includes a significant number of nonce and capability checks, there are notable areas of concern. The presence of a dangerous function like 'preg_replace(/e)' is a red flag, and the taint analysis revealing two high-severity flows with unsanitized paths indicates a potential for vulnerabilities that could be exploited. The plugin's vulnerability history, with four past CVEs including one critical and one high severity, further reinforces the need for caution, suggesting a pattern of past security weaknesses that require ongoing vigilance.
Despite the positive aspects like a zero attack surface from direct entry points and a lack of external HTTP requests, the identified code signals and taint analysis issues, coupled with the historical vulnerability record, mean this plugin should be approached with care. The fact that all past CVEs are currently patched is a positive sign, but the underlying patterns of past vulnerabilities suggest that diligent monitoring and prompt updating are crucial for maintaining a secure WordPress environment when using this plugin.
Key Concerns
- High severity taint flow with unsanitized path
- High severity taint flow with unsanitized path
- Dangerous function: preg_replace(/e)
- Output escaping only 68% properly escaped
- Past critical CVE (even if patched)
- Past high CVE (even if patched)
- Bundled outdated library: Freemius v1.0
Post Snippets – Custom WordPress Code Snippets Customizer Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Post Snippets <= 4.0.11 - Cross-Site Request Forgery
Post Snippets <= 4.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'snippet_content'
Post Snippets <= 3.1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Post Snippets – Custom WordPress Code Snippets Customizer Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Post Snippets – Custom WordPress Code Snippets Customizer Attack Surface
WordPress Hooks 35
Maintenance & Trust
Post Snippets – Custom WordPress Code Snippets Customizer Maintenance & Trust
Maintenance Signals
Community Trust
Post Snippets – Custom WordPress Code Snippets Customizer Alternatives
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
WP Coder – Insert & Manage Code Snippets
wp-coder
Snippets made simple — easily insert and manage custom PHP, CSS, JS & HTML without coding in theme files.
flodjiContacts
flodjicontacts-lite
So wirds benutzt: <code>[contact-box]</code> Dazu gibt es dann unter jedem Artikel eine Metabox über die die Contact Box befüllt wird.
Clipboard Snippet Copier
clipboard-snippet-copier
Copy shortcodes or code snippets to clipboard with a single click using AJAX – without displaying the actual code.
HTMLPress
htmlpress
Simple HTML snippets generator and use it with shortcode.
Post Snippets – Custom WordPress Code Snippets Customizer Developer Profile
84 plugins · 1.4M total installs
How We Detect Post Snippets – Custom WordPress Code Snippets Customizer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-snippets/assets/css/admin.css/wp-content/plugins/post-snippets/assets/css/frontend.css/wp-content/plugins/post-snippets/assets/js/admin.js/wp-content/plugins/post-snippets/assets/js/frontend.js/wp-content/plugins/post-snippets/assets/js/scripts.js/wp-content/plugins/post-snippets/assets/js/admin.js/wp-content/plugins/post-snippets/assets/js/frontend.js/wp-content/plugins/post-snippets/assets/js/scripts.jspost-snippets/assets/css/admin.css?ver=post-snippets/assets/css/frontend.css?ver=post-snippets/assets/js/admin.js?ver=post-snippets/assets/js/frontend.js?ver=post-snippets/assets/js/scripts.js?ver=HTML / DOM Fingerprints
ps-snippetspost-snippets-wrap<!-- Post Snippet: {{snippet_name}} --><!-- End Post Snippet: {{snippet_name}} -->data-snippet-iddata-post-idpostSnippetsFrontendps_vars/wp-json/post-snippets/v1/snippets/wp-json/post-snippets/v1/settings[post_snippet][post_snippet id=""[post_snippet name=""