Shop The Posts Security & Risk Analysis

wordpress.org/plugins/shop-the-posts

Here is a short description of the plugin. This should be no more than 150 characters. No markup here.

10 active installs v1.0.0 PHP 5.6+ WP 4.5+ Updated Jul 28, 2018
blogpostsshopsinglewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shop The Posts Safe to Use in 2026?

Generally Safe

Score 85/100

Shop The Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The shop-the-posts plugin v1.0.0 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for SQL queries are positive indicators. The high percentage of properly escaped output further suggests a diligent approach to preventing common vulnerabilities like Cross-Site Scripting (XSS). The plugin also has no recorded vulnerability history, which is a strong positive signal regarding its past security and maintenance.

However, there are specific areas of concern that temper the otherwise positive assessment. The plugin lacks any nonce checks or capability checks. While the attack surface appears small (one shortcode) and has no explicitly unprotected entry points in this snapshot, the absence of these fundamental security mechanisms means that even simple operations could potentially be exploited by unauthenticated or unauthorized users if the shortcode's functionality were to interact with sensitive data or actions. The taint analysis also shows zero flows analyzed, which is unusual for a plugin with any functionality and could indicate incomplete analysis or a lack of complex data processing that could be susceptible to taint.

In conclusion, shop-the-posts v1.0.0 shows promising development practices with secure SQL handling and output escaping. The lack of past vulnerabilities is a significant strength. Nevertheless, the complete absence of nonce and capability checks, coupled with the zero taint flow analysis, represents a notable security gap. Future versions should prioritize implementing these checks to ensure robust authorization and prevent potential privilege escalation or unauthorized actions, even if the current attack surface is minimal.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Taint analysis: 0 flows analyzed
Vulnerabilities
None known

Shop The Posts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Shop The Posts Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Shop The Posts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
28 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped31 total outputs
Attack Surface

Shop The Posts Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[shop_the_posts] includes\class-shop-the-posts.php:188
WordPress Hooks 10
actionadd_meta_boxesadmin\class-shop-the-posts-metaboxes.php:37
actionsave_postadmin\class-shop-the-posts-metaboxes.php:38
actionplugins_loadedincludes\class-shop-the-posts.php:149
actionadmin_enqueue_scriptsincludes\class-shop-the-posts.php:164
actionadmin_enqueue_scriptsincludes\class-shop-the-posts.php:165
actionload-post.phpincludes\class-shop-the-posts.php:168
actionload-post-new.phpincludes\class-shop-the-posts.php:169
actionwp_enqueue_scriptsincludes\class-shop-the-posts.php:184
actionwp_enqueue_scriptsincludes\class-shop-the-posts.php:185
actionthe_contentincludes\class-shop-the-posts.php:186
Maintenance & Trust

Shop The Posts Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 28, 2018
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Shop The Posts Developer Profile

Codeless

8 plugins · 2K total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shop The Posts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shop-the-posts/css/shop-the-posts-admin.css/wp-content/plugins/shop-the-posts/css/shop-the-posts-metaboxes.css/wp-content/plugins/shop-the-posts/js/shop-the-posts-admin.js/wp-content/plugins/shop-the-posts/js/shop-the-posts-metaboxes.js
Script Paths
/wp-content/plugins/shop-the-posts/js/shop-the-posts-admin.js/wp-content/plugins/shop-the-posts/js/shop-the-posts-metaboxes.js
Version Parameters
shop-the-posts-admin.css?ver=shop-the-posts-metaboxes.css?ver=shop-the-posts-admin.js?ver=shop-the-posts-metaboxes.js?ver=

HTML / DOM Fingerprints

CSS Classes
shop-the-posts-metaboxes
JS Globals
shop_the_posts_admin
FAQ

Frequently Asked Questions about Shop The Posts