
Post Type Spotlight Security & Risk Analysis
wordpress.org/plugins/post-type-spotlightx-release-please-start-version Stable tag: 3.0.3 x-release-please-end License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.
Is Post Type Spotlight Safe to Use in 2026?
Generally Safe
Score 85/100Post Type Spotlight has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "post-type-spotlight" v3.0.3 exhibits a very strong security posture based on the provided static analysis. There are no identified vulnerabilities in its attack surface, dangerous functions, SQL queries, output escaping, file operations, or external HTTP requests. The presence of nonce and capability checks further reinforces good security practices. The absence of any recorded CVEs in its vulnerability history, coupled with the clean code signals, suggests a mature and secure codebase that has likely been well-maintained and vetted.
However, it's important to note that the static analysis did not reveal any taint flows. While this is an excellent sign, it doesn't entirely eliminate the possibility of complex, context-dependent vulnerabilities that might be missed by automated tools. The limited attack surface is a significant strength, but the fact that there are *zero* entry points without authentication checks is also a data point worth considering, implying a very minimal feature set for public interaction. Overall, this plugin appears to be exceptionally secure.
Post Type Spotlight Security Vulnerabilities
Post Type Spotlight Code Analysis
Output Escaping
Post Type Spotlight Attack Surface
WordPress Hooks 22
Maintenance & Trust
Post Type Spotlight Maintenance & Trust
Maintenance Signals
Community Trust
Post Type Spotlight Alternatives
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Featured Posts and Custom Posts
featured-posts-and-custom-posts
Allows the user to feature posts and custom posts. When a post is featured it gets the post metta _jsFeaturedPost.
WP Featured News – Custom Posts Listing Elements
wp-featured-news-custom-posts-listing-elements
WP Featured News plugin allows you to display your posts anywhere of your web-pages with 10 powerful and creatively designed post blocks.
MB Custom Post Types & Custom Taxonomies
mb-custom-post-type
Create and manage custom post types and custom taxonomies with an easy-to-use UI in WordPress.
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Post Type Spotlight Developer Profile
9 plugins · 21K total installs
How We Detect Post Type Spotlight
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-type-spotlight/build/index.js/wp-content/plugins/post-type-spotlight/build/index.csspost-type-spotlight/build/index.js?ver=post-type-spotlight/build/index.css?ver=HTML / DOM Fingerprints
wp-block-post-type-spotlight-featured-listis-featured-postpost-type-spotlight-featured-postdata-namespace="post-type-spotlight/featured-list"data-querytypedata-perpagedata-orderbydata-orderpostTypeSpotlightpts_featured_post_types_settings/wp-json/post-type-spotlight/v1/all