
Relations Post Types Security & Risk Analysis
wordpress.org/plugins/relation-post-typesThis plugin allow to build relation between 2 custom types (posts, page, custom), very useful for manage related content on CMS type website.
Is Relations Post Types Safe to Use in 2026?
Generally Safe
Score 85/100Relations Post Types has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "relation-post-types" plugin version 1.3.1 presents a mixed security posture. While it boasts no known CVEs and a good percentage of SQL queries using prepared statements, several concerning code signals and taint analysis results raise flags. The presence of dangerous functions like 'unserialize' and 'create_function' is a significant risk, as these can be exploited for code injection if not handled with extreme caution and proper sanitization. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, indicating potential for data manipulation or unauthorized access. The plugin also exposes an unprotected AJAX handler, which is a direct entry point for potential attacks. The lack of capability checks on this entry point further exacerbates the risk. While the absence of past vulnerabilities is positive, it doesn't negate the inherent risks identified in the current static analysis. The overall security is weakened by the presence of critical code signals and potential taint flows, despite a low attack surface and good SQL practices.
Key Concerns
- Unprotected AJAX handler
- High severity taint flows (2)
- Dangerous function: unserialize
- Dangerous function: create_function
- Low output escaping percentage
- No capability checks on entry points
Relations Post Types Security Vulnerabilities
Relations Post Types Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Relations Post Types Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
Relations Post Types Maintenance & Trust
Maintenance Signals
Community Trust
Relations Post Types Alternatives
Posts 2 Posts
posts-to-posts
Efficient many-to-many connections between posts, pages, custom post types, users.
More Types
more-types
Adds any number of extra Post types, besides Post and Page, for the WordPess Admin. Also allows for special editing rights for specific User roles for …
SuperCPT
super-cpt
Insanely easy and attractive custom post types, custom post meta, and custom taxonomies
Posts 2 Posts Relationships
posts-2-posts-relationships
Efficient many-to-many connections between posts, pages and custom post types.
KontrolWP – Kontrol WordPress Developer Kit
kontrolwp
KontrolWP is an advanced Wordpress plugin for developers. Easily create CMS sites using advanced custom fields, custom post types, SEO and more.
Relations Post Types Developer Profile
3 plugins · 10K total installs
How We Detect Relations Post Types
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/relation-post-types/ressources/js/admin-post.min.js/wp-content/plugins/relation-post-types/ressources/js/admin-post.min.jsrelation-post-types/ressources/js/admin-post.min.js?ver=HTML / DOM Fingerprints
rpt