Add Custom Post Type into Post Query Security & Risk Analysis

wordpress.org/plugins/post-type-modifier-simple

Deprecated. Use https://wordpress.org/plugins/additional-wp-tweaks-options/

10 active installs v1.1o PHP + WP 4.4+ Updated Unknown
customincludepostquerytype
100
A · Safe
CVEs total1
Unpatched0
Last CVEAug 1, 2022
Safety Verdict

Is Add Custom Post Type into Post Query Safe to Use in 2026?

Generally Safe

Score 100/100

Add Custom Post Type into Post Query has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 1, 2022
Risk Assessment

The static analysis of 'post-type-modifier-simple' v1.1o reveals a strong adherence to secure coding practices, with no identified dangerous functions, SQL injection vulnerabilities, or unescaped output. The plugin also has a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, and all identified SQL queries utilize prepared statements. This indicates a generally robust and secure code foundation.

However, the vulnerability history presents a significant concern. The plugin has a known CVE, specifically a medium severity Cross-Site Scripting (XSS) vulnerability that was last patched on August 1, 2022. While this specific vulnerability is reported as currently unpatched, its presence suggests a potential for insecure input handling or output rendering, even if not immediately apparent in the current static analysis. The absence of explicit capability checks and nonce checks across its (albeit zero) entry points, combined with the past XSS vulnerability, warrants careful consideration.

Key Concerns

  • Past medium XSS vulnerability remains unpatched
  • Missing capability checks on entry points
  • Missing nonce checks on entry points
Vulnerabilities
1

Add Custom Post Type into Post Query Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-bfb329da-00df-4178-ad40-9b0b718dc30e-post-type-modifier-simplemedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Add Custom Post Type into Post Query <= 1.03 - Reflected Cross-Site Scripting

Aug 1, 2022 Patched in 1.04 (540d)
Code Analysis
Analyzed Mar 16, 2026

Add Custom Post Type into Post Query Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Add Custom Post Type into Post Query Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Add Custom Post Type into Post Query Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Add Custom Post Type into Post Query Developer Profile

Puvox Software

16 plugins · 51K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
540 days
View full developer profile
Detection Fingerprints

How We Detect Add Custom Post Type into Post Query

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
post-type-modifier-simple/style.css?ver=post-type-modifier-simple/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Add Custom Post Type into Post Query