
Posts by Category Security & Risk Analysis
wordpress.org/plugins/posts-by-categoryDisplay a list of posts from a specific category or tag.
Is Posts by Category Safe to Use in 2026?
Generally Safe
Score 85/100Posts by Category has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'posts-by-category' plugin version 1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, unescaped output, file operations, and external HTTP requests is commendable. The plugin also correctly uses capability checks, indicating an effort to control access to its functionalities. Furthermore, the lack of any recorded vulnerabilities, including CVEs of any severity, is a positive indicator of its historical stability.
However, a key area of concern is the complete absence of nonce checks, particularly given that there is one shortcode entry point. While the static analysis reports no unprotected entry points and the capability check is present, the lack of nonce checks leaves the shortcode susceptible to CSRF (Cross-Site Request Forgery) attacks if it performs any sensitive actions. This is the primary weakness identified in the current analysis. The fact that no taint flows were detected suggests that the code is likely well-sanitized for the operations it performs, but the absence of nonce checks is a missed security control.
In conclusion, 'posts-by-category' v1.0.0 demonstrates good coding practices in many areas and has a clean vulnerability history. The presence of capability checks is a significant strength. The primary area for improvement, and the source of a security deduction, is the missing nonce check for its shortcode, which introduces a potential CSRF vulnerability. Addressing this would further solidify its security. The absence of other common vulnerabilities and the clean history are positive signs.
Key Concerns
- Missing nonce check on shortcode
Posts by Category Security Vulnerabilities
Posts by Category Code Analysis
Posts by Category Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Posts by Category Maintenance & Trust
Maintenance Signals
Community Trust
Posts by Category Alternatives
WP Filter Posts – List Posts by Categories, Tags, Authors and dates
wp-filter-posts
Generate shortcode to list posts based on ids, categories, authors, tags or dates.
Post Listing
post-listing
Display list and grid of posts.
Custom Recent Posts Widget
custom-recent-posts-widget
A widget to show recent posts list based on categories or tags
xili-tidy-tags
xili-tidy-tags
xili-tidy-tags is a tool for grouping tags by semantic groups or by language and for creating tidy tag clouds.
Display Posts As List, Grid, Thumbs
ultimate-content-views
This plugin lets you list posts by category, author, tags, and more, using a shortcode on posts, pages, or widgets with plenty of customization option …
Posts by Category Developer Profile
1 plugin · 100 total installs
How We Detect Posts by Category
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<h3><h4><ul><li><a href="