
Post Types Unlimited Security & Risk Analysis
wordpress.org/plugins/post-types-unlimitedCreate unlimited custom post types and custom taxonomies.
Is Post Types Unlimited Safe to Use in 2026?
Generally Safe
Score 100/100Post Types Unlimited has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the 'post-types-unlimited' plugin v1.2.8 reveals a strong adherence to secure coding practices in several key areas. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code demonstrates a commitment to security by exclusively using prepared statements for all SQL queries and reporting zero critical or high severity taint flows. The lack of recorded vulnerabilities, including critical and high severity ones, in its history is also a positive indicator of its past security performance.
However, a notable concern arises from the low percentage of properly escaped output (7%). With 28 total outputs analyzed, this means a significant number of them are potentially susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. The complete absence of capability checks is another potential weakness, as it suggests that access to certain functionalities might not be properly restricted based on user roles, potentially leading to unauthorized actions if an attacker can bypass other (non-existent) entry points.
Overall, the plugin exhibits a good foundation for security by minimizing its attack surface and using prepared statements. Nevertheless, the significant lack of output escaping and the absence of capability checks present tangible security risks that should be addressed to improve its security posture.
Key Concerns
- Low output escaping rate
- Missing capability checks
Post Types Unlimited Security Vulnerabilities
Post Types Unlimited Code Analysis
Output Escaping
Post Types Unlimited Attack Surface
WordPress Hooks 1
Maintenance & Trust
Post Types Unlimited Maintenance & Trust
Maintenance Signals
Community Trust
Post Types Unlimited Alternatives
Custom post types, Custom Fields & more
custom-post-types
Custom Post Types, Custom Fields, Custom Taxonomies, Custom Templates, Custom Admin Pages, Custom Admin Notices. Directly from the WP dashboard.
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
MB Custom Post Types & Custom Taxonomies
mb-custom-post-type
Create and manage custom post types and custom taxonomies with an easy-to-use UI in WordPress.
CubeWP Framework
cubewp-framework
CubeWP is an end-to-end dynamic content framework for WordPress to help you shrink time and cut cost of development up to 90%.
Post Types Unlimited Developer Profile
13 plugins · 22K total installs
How We Detect Post Types Unlimited
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-types-unlimited/assets/css/ptu-metaboxes.css/wp-content/plugins/post-types-unlimited/assets/js/ptu-metaboxes.js/wp-content/plugins/post-types-unlimited/assets/js/ptu-metaboxes.jsptu-metaboxes=1.2.8HTML / DOM Fingerprints
ptu-metaboxptu-metabox-tabsptu-metabox-tabptu-metabox-tab-linkptu-metabox-sectionsptu-metabox-sectionaria-controlsaria-selecteddata-ptu-tab-conditionrole