Query Loop Post Selector Security & Risk Analysis

wordpress.org/plugins/query-loop-post-selector

A native query loop extension that adds a new option in the filter that allows user to specifically pick certain posts to display

500 active installs v1.0.5 PHP 7.0+ WP 5.8+ Updated May 8, 2025
blockquery-loopquery-loop-post-selector
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Query Loop Post Selector Safe to Use in 2026?

Generally Safe

Score 100/100

Query Loop Post Selector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "query-loop-post-selector" plugin v1.0.5 exhibits a strong security posture. The absence of any identified attack surface points, dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or exploitable taint flows is highly commendable. This indicates diligent coding practices and a focus on secure development within the plugin.

The plugin's vulnerability history is also clean, with no recorded CVEs, which further reinforces its current security state. The lack of any past vulnerabilities suggests a consistent commitment to security by the developers or a lack of past scrutiny that has revealed issues. However, the complete absence of nonces and capability checks across all entry points, while currently not leading to any identified vulnerabilities due to the zero attack surface, represents a potential future risk. Should new entry points be added or existing ones become exposed, this lack of robust access control could become a significant weakness.

In conclusion, "query-loop-post-selector" v1.0.5 appears to be a very secure plugin in its current version and state. The code analysis reveals no immediate threats. The only area of concern is the foundational absence of nonces and capability checks, which, while not an issue now, could pose a risk if the plugin's functionality expands or its interaction with the WordPress core changes.

Key Concerns

  • No nonces found
  • No capability checks found
Vulnerabilities
None known

Query Loop Post Selector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Query Loop Post Selector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Query Loop Post Selector Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionenqueue_block_editor_assetsquery-loop-post-selector.php:42
filterquery_loop_block_query_varsquery-loop-post-selector.php:43
actioninitquery-loop-post-selector.php:46
Maintenance & Trust

Query Loop Post Selector Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMay 8, 2025
PHP min version7.0
Downloads5K

Community Trust

Rating100/100
Number of ratings5
Active installs500
Developer Profile

Query Loop Post Selector Developer Profile

Small Plugins

7 plugins · 590 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Query Loop Post Selector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/query-loop-post-selector/build/index.js
Script Paths
/wp-content/plugins/query-loop-post-selector/build/index.js
Version Parameters
query-loop-post-selector/build/index.js?ver=

HTML / DOM Fingerprints

Data Attributes
qlpspSelectivePosts
REST Endpoints
/wp-json/query-loop-post-selector/
FAQ

Frequently Asked Questions about Query Loop Post Selector