
Post Type Converter Security & Risk Analysis
wordpress.org/plugins/post-type-converterAllows you to convert the post type of objects while in the edit screen.
Is Post Type Converter Safe to Use in 2026?
Use With Caution
Score 63/100Post Type Converter has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'post-type-converter' plugin version 0.6 exhibits a mixed security posture. On the positive side, the static analysis shows a commendable absence of dangerous functions, SQL injection vulnerabilities through prepared statements, file operations, and external HTTP requests. It also correctly implements nonce and capability checks on its limited entry points. However, a significant concern arises from the lack of output escaping on all identified outputs, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output.
The taint analysis reveals a flow with unsanitized paths, indicating a potential for unintended behavior or security issues related to path manipulation, though no critical or high severity issues were found in this specific analysis. The plugin's vulnerability history is a more pressing concern, with one known medium severity CVE that is currently unpatched. The fact that this vulnerability is a Cross-Site Request Forgery (CSRF) is notable, especially given the static analysis found nonce checks present, suggesting a potential bypass or a different attack vector.
In conclusion, while 'post-type-converter' v0.6 demonstrates good practices in areas like input sanitization for SQL and a controlled attack surface, the unpatched CVE, combined with the complete lack of output escaping, presents a notable risk. The plugin is advised to address the unpatched vulnerability and implement proper output escaping to mitigate potential XSS and CSRF risks.
Key Concerns
- Unpatched CVE found
- Output escaping missing on all outputs
- Taint flow with unsanitized paths
Post Type Converter Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Post Type Converter <= 0.6 - Cross-Site Request Forgery
Post Type Converter Code Analysis
Output Escaping
Data Flow Analysis
Post Type Converter Attack Surface
WordPress Hooks 5
Maintenance & Trust
Post Type Converter Maintenance & Trust
Maintenance Signals
Community Trust
Post Type Converter Alternatives
Post Types Unlimited
post-types-unlimited
Create unlimited custom post types and custom taxonomies.
Simple CPT
simple-cpt
Simple CPT provides an easy to use interface for registering and managing custom post types and custom taxonomies.
Custom post types, Custom Fields & more
custom-post-types
Custom Post Types, Custom Fields, Custom Taxonomies, Custom Templates, Custom Admin Pages, Custom Admin Notices. Directly from the WP dashboard.
Custom Post Type Editor
cpt-editor
Customize the text labels, menu names or description for any registered custom post type using a simple Dashboard user interface.
Custom Post Type Sticky
custom-post-type-sticky
Extends sticky post functionality to custom post types in a way that is identical to default posts.
Post Type Converter Developer Profile
4 plugins · 1K total installs
How We Detect Post Type Converter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-type-converter/js/post-type-converter.js/wp-content/plugins/post-type-converter/js/post-type-converter.jsHTML / DOM Fingerprints
id="convert_post_type"name="convert_post_type"id="convert-post-type"script_vars