
Postqueue Security & Risk Analysis
wordpress.org/plugins/postqueueAllows you to create you very own loop order of posts
Is Postqueue Safe to Use in 2026?
Generally Safe
Score 100/100Postqueue has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The postqueue v1.5.1 plugin exhibits a mixed security posture. While it avoids dangerous functions and performs the vast majority of its SQL queries using prepared statements, several areas raise concerns. A significant portion of the attack surface, specifically 3 out of 9 AJAX handlers, are not protected by authentication checks. This presents a direct risk of unauthorized actions if these handlers are exploitable. Furthermore, the taint analysis indicates flows with unsanitized paths, although currently without critical or high severity, this warrants attention as it could lead to vulnerabilities if further exploited. The plugin's lack of recorded vulnerabilities in its history is a positive sign, suggesting a history of good security practices or a lack of exploitation. However, this doesn't negate the risks identified in the static analysis, particularly the unprotected AJAX endpoints.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths (taint analysis)
- Low percentage of properly escaped output
- Missing nonce checks on AJAX handlers
Postqueue Security Vulnerabilities
Postqueue Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Postqueue Attack Surface
AJAX Handlers 9
WordPress Hooks 17
Maintenance & Trust
Postqueue Maintenance & Trust
Maintenance Signals
Community Trust
Postqueue Alternatives
Postqueue Feeds
postqueue-feeds
Gives you feeds for Postqueues.
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Simple Custom Post Order
simple-custom-post-order
Easily reorder posts, pages, custom post types, and taxonomies with intuitive drag-and-drop sorting in the WordPress admin.
Flexible SSL for CloudFlare
cloudflare-flexible-ssl
Fix For Redirect Loops on WordPress with CloudFlare's Flexible/Universal SSL.
Elementor Custom Skin
ele-custom-skin
Create new skins for Elementor PRO 3.x page builder. Design your own skins for Post and Post Archive Widgets using Elementor Loop Templates.
Postqueue Developer Profile
22 plugins · 2K total installs
How We Detect Postqueue
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/postqueue/dist/meta-box.css/wp-content/plugins/postqueue/dist/meta-box.js/wp-content/plugins/postqueue/dist/postqueue-editor.css/wp-content/plugins/postqueue/dist/postqueue-editor.js/wp-content/plugins/postqueue/dist/meta-box.js/wp-content/plugins/postqueue/dist/postqueue-editor.jspostqueue-metabox-csspostqueue-metaboxpostqueue-csspostqueue-jsHTML / DOM Fingerprints
postqueue-metaboxpostqueue-editordata-postqueue-editor-loadedPostqueueMetaBoxL10n/wp-json/postqueue/v1/items/wp-json/postqueue/v1/items/(?P<id>[\d]+)/wp-json/postqueue/v1/postqueue/(?P<id>[\d]+)/wp-json/postqueue/v1/postqueue/wp-json/postqueue/v1/queue[postqueue]