PostLay – Automatic Blog Post Layout Addon For WordPress Security & Risk Analysis

wordpress.org/plugins/postlay-automatic-blog-post-layout-addon

Postlay Automatic Blog Posts Grid is best wordpress plugin to display blog posts at your website! If You use this plugin you will get blog posts aweso …

0 active installs v1.1 PHP 7.2+ WP 5.2+ Updated Sep 13, 2022
blogblog-designblog-gridblog-layoutpostlay-blog-posts-grid
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PostLay – Automatic Blog Post Layout Addon For WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

PostLay – Automatic Blog Post Layout Addon For WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The postlay-automatic-blog-post-layout-addon v1.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and a high percentage of properly escaped output are excellent indicators of secure coding practices. Furthermore, the lack of file operations, external HTTP requests, and no recorded vulnerabilities in its history suggest a well-maintained and robust codebase. The limited attack surface, consisting of a single shortcode with no explicit authentication checks, is a concern but its impact is mitigated by the overall lack of critical code signals. The absence of taint analysis flows and dangerous functions further reinforces the impression of a secure plugin. The plugin's vulnerability history is clean, indicating a commitment to security or a lack of past issues, which is a positive sign. However, the presence of a shortcode without any explicit capability checks or nonce validation represents a potential, albeit low-level, risk of unauthorized execution if it were to interact with sensitive functionality, which is not evident from the provided data.

Key Concerns

  • Shortcode without explicit capability checks
Vulnerabilities
None known

PostLay – Automatic Blog Post Layout Addon For WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PostLay – Automatic Blog Post Layout Addon For WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
136 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped142 total outputs
Attack Surface

PostLay – Automatic Blog Post Layout Addon For WordPress Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[postlay_posts] postlay-wp-blog-layout.php:194
WordPress Hooks 8
actionadmin_menuinc\functions.php:18
actionwp_footerinc\netroics-dynamic-style.php:221
actionwp_enqueue_scriptspostlay-wp-blog-layout.php:31
actionadmin_enqueue_scriptspostlay-wp-blog-layout.php:41
actionadmin_enqueue_scriptspostlay-wp-blog-layout.php:46
actioninitpostlay-wp-blog-layout.php:116
actioninitpostlay-wp-blog-layout.php:197
actionadmin_initpostlay-wp-blog-layout.php:202
Maintenance & Trust

PostLay – Automatic Blog Post Layout Addon For WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 13, 2022
PHP min version7.2
Downloads785

Community Trust

Rating100/100
Number of ratings3
Active installs0
Developer Profile

PostLay – Automatic Blog Post Layout Addon For WordPress Developer Profile

Netro Systems

2 plugins · 100 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PostLay – Automatic Blog Post Layout Addon For WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/postlay-automatic-blog-post-layout-addon/css/ncmbp-style.css/wp-content/plugins/postlay-automatic-blog-post-layout-addon/css/ncmbp-font-awesome.min.css/wp-content/plugins/postlay-automatic-blog-post-layout-addon/css/ncmbp-admin-style.css/wp-content/plugins/postlay-automatic-blog-post-layout-addon/js/my-script.js/wp-content/plugins/postlay-automatic-blog-post-layout-addon/js/cp-active.js/wp-content/plugins/postlay-automatic-blog-post-layout-addon/img/menu-icon.png

HTML / DOM Fingerprints

CSS Classes
features__lists_mainfeatures__listsfeature__singlefeature_single_detailsncmbp_read_btnncmbp_pagination
Shortcode Output
[postlay_posts]
FAQ

Frequently Asked Questions about PostLay – Automatic Blog Post Layout Addon For WordPress