
Posts List Security & Risk Analysis
wordpress.org/plugins/posts-listAdds a posts (or pages) list of your blog pages (or posts) by entering the shortcode [posts-list].
Is Posts List Safe to Use in 2026?
Generally Safe
Score 85/100Posts List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'posts-list' plugin version 0.4.2 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and proper output escaping are significant strengths. Furthermore, the plugin demonstrates good practice by not performing file operations or external HTTP requests. The lack of any recorded vulnerabilities in its history, including critical or high-severity ones, suggests a history of secure development and maintenance.
Despite the overall positive assessment, a few areas warrant attention. The presence of two shortcodes represents an attack surface, and while the static analysis reports zero unprotected entry points, the absence of explicitly stated nonce or capability checks on these shortcodes raises a potential concern. If these shortcodes are intended to handle user input or perform sensitive actions, the lack of these security mechanisms could introduce vulnerabilities. However, without more specific details on the shortcode functionality, it's difficult to quantify the exact risk.
In conclusion, the 'posts-list' plugin appears to be a secure option, with a strong emphasis on safe coding practices and a clean vulnerability history. The primary area for potential improvement lies in ensuring that all shortcodes, regardless of perceived sensitivity, are adequately protected with nonce and capability checks to mitigate any unforeseen risks.
Key Concerns
- Shortcodes present without explicit nonce/capability checks mentioned
Posts List Security Vulnerabilities
Posts List Code Analysis
SQL Query Safety
Output Escaping
Posts List Attack Surface
Shortcodes 2
Maintenance & Trust
Posts List Maintenance & Trust
Maintenance Signals
Community Trust
Posts List Alternatives
list-posts WordPress Plugin
list-posts
This is a a plugin that lists the latest posts on any page (or post). It does not use an iframe. It is extremely simple, and honors permissions and pa …
CC-List-Posts
cc-list-posts
This plugin adds similar to wp_list_pages, missing function and shortcode wp_list_posts with pagination support.
Elementor Custom Skin
ele-custom-skin
Create new skins for Elementor PRO 3.x page builder. Design your own skins for Post and Post Archive Widgets using Elementor Loop Templates.
VK Link Target Controller
vk-link-target-controller
Redirect your visitors to another page than the post content when they click on the post title.
CC Child Pages
cc-child-pages
Display WordPress child pages in a responsive grid or list using a shortcode, Gutenberg block or Elementor widget.
Posts List Developer Profile
7 plugins · 12K total installs
How We Detect Posts List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
archive-listarchive-list-item[posts-list][posts-list type="page"][posts-list type="attachment"][posts-list sort="asc"]