
Requird Security & Risk Analysis
wordpress.org/plugins/requirdRequire users to fill selected fields before posting.
Is Requird Safe to Use in 2026?
Generally Safe
Score 100/100Requird has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "requird" v1.3 plugin exhibits a generally positive security posture based on the static analysis provided. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Crucially, the lack of any reported vulnerabilities (CVEs) historically and in the current state further strengthens this impression. The plugin also demonstrates some good practices like using prepared statements for SQL queries and a capability check.
However, there are notable areas for concern. The most significant is the complete lack of output escaping for all identified outputs. This represents a critical risk, as unsanitized output can lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious code into web pages viewed by other users. The absence of nonce checks on any entry points is also a weakness, potentially exposing the plugin to Cross-Site Request Forgery (CSRF) attacks if any actionable operations were present.
While the plugin's history is clean, the identified issues in output escaping and nonce checks create potential vulnerabilities that could be exploited. A clean vulnerability history is positive, but it doesn't negate the risks identified in the current code analysis. The plugin needs to address the output escaping issue to significantly improve its security.
Key Concerns
- All outputs are unescaped
- No nonce checks on entry points
Requird Security Vulnerabilities
Requird Code Analysis
Output Escaping
Requird Attack Surface
WordPress Hooks 6
Maintenance & Trust
Requird Maintenance & Trust
Maintenance Signals
Community Trust
Requird Alternatives
Require Post Tags
require-post-tags
Require users to add at least one post tag before saving a draft, updating a post, or publishing a post. This applies to normal posts and may not be …
Force Post Category Selection
force-post-category-selection
This is simple plugin which forces the users to select atleast one category from the list while publishing a new post.
Force Post Title
force-post-title
This is simple plugin which forces the users to write POST title in Add New Post page.
wpPostPageManager
wppostpagemanager
Enables to add post type links (posts, pages, custom post types etc) and to change the titles in admin main menu.
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
post-expirator
PublishPress Future can make scheduled changes to your content. You can unpublish posts, move posts to a new status, update the categories, and more.
Requird Developer Profile
1 plugin · 10 total installs
How We Detect Requird
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/requird/requird.js/wp-content/plugins/requird/requird.jsHTML / DOM Fingerprints
requirdOptions