
Secret Posts Security & Risk Analysis
wordpress.org/plugins/secret-postsMark WordPress posts as private after a specified number of page views or time.
Is Secret Posts Safe to Use in 2026?
Generally Safe
Score 85/100Secret Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "secret-posts" v1.0 plugin exhibits a seemingly strong security posture at first glance, with no identified CVEs in its history and a clean static analysis report regarding dangerous functions, SQL queries, file operations, and external HTTP requests. The absence of AJAX handlers, REST API routes, shortcodes, and cron events suggests a minimal attack surface. However, the static analysis does raise a concern: 50% of output is not properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if the unescaped output is rendered within a web page. Furthermore, the lack of any identified taint flows, while positive, could also be a consequence of the limited complexity or entry points of the plugin. The vulnerability history is positive, showing no past issues, which could indicate good development practices or a lack of extensive security testing. Overall, while the plugin is free of known severe vulnerabilities and follows good practices in many areas, the unescaped output is a significant weakness that requires immediate attention to prevent potential XSS attacks.
Key Concerns
- 50% of output not properly escaped
Secret Posts Security Vulnerabilities
Secret Posts Code Analysis
Output Escaping
Secret Posts Attack Surface
WordPress Hooks 3
Maintenance & Trust
Secret Posts Maintenance & Trust
Maintenance Signals
Community Trust
Secret Posts Alternatives
Hide Posts
whp-hide-posts
Allows you to hide any posts on the home page, category page, search page, tags page, authors page, RSS Feed, REST API, XML sitemaps, SEO integrations …
Unlist Posts & Pages
unlist-posts
Hide posts, pages or custom items from your site and make them accessible only with the direct link.
No External Links
mihdan-no-external-links
Convert external links into internal links, site wide or post/page specific. Add NoFollow, Click logging, and more...
Hide from Search
mpress-hide-from-search
Hide individual WordPress pages from search engines and/or WordPress searches, such as confirmation and download pages.
Private Store for WooCommerce B2B & Wholesale by B2BKing
b2bking-private-store-for-woocommerce
Hide prices for logged out users, or even hide the store completely! Perfect solution for Private, B2B, and Wholesale stores.
Secret Posts Developer Profile
6 plugins · 70 total installs
How We Detect Secret Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
name="secret_posts_views"name="secret_posts_date"