
Posts Columns Manager Security & Risk Analysis
wordpress.org/plugins/posts-columns-managerDid you ever want to add some custom columns to the posts overview page?
Is Posts Columns Manager Safe to Use in 2026?
Generally Safe
Score 85/100Posts Columns Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "posts-columns-manager" v1.7.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. The code analysis further shows no dangerous functions, file operations, or external HTTP requests. Crucially, all identified SQL queries utilize prepared statements, and there is no record of known vulnerabilities (CVEs) for this plugin, suggesting a history of responsible development and maintenance.
However, a notable concern arises from the output escaping. With 38 total outputs, only 21% are properly escaped. This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, where unsanitized user input could be injected into the frontend of the website. The lack of any recorded nonce checks or capability checks, while not directly tied to identified entry points in this analysis, is a general security practice that is not being followed, leaving potential for future vulnerabilities if entry points are introduced without proper safeguards.
In conclusion, while the plugin's attack surface and direct vulnerabilities appear low, the inadequate output escaping presents a tangible and significant risk. The absence of a vulnerability history is a strength, but the identified weakness in output sanitization requires attention to ensure a robust security profile.
Key Concerns
- Low output escaping rate (21%)
- Missing nonce checks
- Missing capability checks
Posts Columns Manager Security Vulnerabilities
Posts Columns Manager Code Analysis
Output Escaping
Posts Columns Manager Attack Surface
WordPress Hooks 11
Maintenance & Trust
Posts Columns Manager Maintenance & Trust
Maintenance Signals
Community Trust
Posts Columns Manager Alternatives
WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer
adminify
Transform your WordPress admin into a fully white-labeled, organized client dashboard. Customize, Dark mode, Secure, Boost productivity, and more.
Three Column Screen Layout
three-column-screen-layout
Three, four and five column screen layouts for the post editor.
The Ultimate WordPress Toolkit – WP Extended
wpextended
SMTP Email, Maintenance Mode, Duplicate Posts & Pages, Duplicate menu, Code Snippets, SVG File upload, Disable Gutenberg, Limit Login Attempts &am …
WYSIWYG Button Manager
wysiwyg-button-manager
Allow the admin to override the default WYSIWYG button bar. Also allow the admin to create a unique 3-row button panel and assign this to a user.
Arunstheme Editorial Notes
arunstheme-editorial-notes
Private editorial notes and status manager for WordPress posts and pages. Filter, track, and manage content workflow easily.
Posts Columns Manager Developer Profile
4 plugins · 800 total installs
How We Detect Posts Columns Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/posts-columns-manager/assets/css/pcm.css/wp-content/plugins/posts-columns-manager/assets/js/pcm.js/wp-content/plugins/posts-columns-manager/assets/js/pcm.jsposts-columns-manager/assets/css/pcm.css?ver=posts-columns-manager/assets/js/pcm.js?ver=HTML / DOM Fingerprints
pcm-settings-tabdata-pcm-post-typePCM_ADMIN