
Post Type Transfer Security & Risk Analysis
wordpress.org/plugins/post-type-transferA simple way to change a post's post-type in WordPress
Is Post Type Transfer Safe to Use in 2026?
Generally Safe
Score 100/100Post Type Transfer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'post-type-transfer' plugin v1.5 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs and the plugin's clean vulnerability record suggest a history of robust security practices. The static analysis reveals no dangerous functions, no direct SQL queries without prepared statements, and no file operations or external HTTP requests, all of which significantly reduce the attack surface. Furthermore, the presence of nonce and capability checks indicates an effort to protect against common WordPress vulnerabilities. The code signals also show a high percentage of properly escaped output, mitigating risks of cross-site scripting (XSS).
While the plugin demonstrates excellent security hygiene, the static analysis reports zero taint flows and zero unsanitized paths. This is generally a positive sign, but it's important to note that the "Total flows analyzed: 0" suggests that the taint analysis might not have been comprehensive or that the plugin's functionality is extremely limited in ways that avoid data flow paths. The absence of AJAX handlers, REST API routes, shortcodes, and cron events contributes to a minimal attack surface. However, a completely zero attack surface can sometimes be an indicator that the plugin's functionality is also very limited, or that more complex interactions might be handled differently. Overall, this version of 'post-type-transfer' appears to be very secure, with no immediate red flags identified in the provided data.
Post Type Transfer Security Vulnerabilities
Post Type Transfer Code Analysis
Output Escaping
Post Type Transfer Attack Surface
WordPress Hooks 10
Maintenance & Trust
Post Type Transfer Maintenance & Trust
Maintenance Signals
Community Trust
Post Type Transfer Alternatives
CubeWP Framework
cubewp-framework
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
All in one demo Export/Import
all-in-one-demo-importexport
Easily export or import your WordPress customizer settings!
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Post Type Transfer Developer Profile
13 plugins · 17K total installs
How We Detect Post Type Transfer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-type-transfer/assets/js/post-type-transfer-quickedit.js/wp-content/plugins/post-type-transfer/assets/css/post-type-transfer-quickedit.csspost-type-transfer/assets/js/post-type-transfer-quickedit.js?ver=post-type-transfer/assets/css/post-type-transfer-quickedit.css?ver=HTML / DOM Fingerprints
inline-edit-col-pttdata-post-type