
Show Content Only Security & Risk Analysis
wordpress.org/plugins/show-content-onlyDisplay only the post or page content, without a theme, sidebars, scripts or stylesheets.
Is Show Content Only Safe to Use in 2026?
Generally Safe
Score 85/100Show Content Only has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'show-content-only' plugin version 1.3.1 exhibits a generally strong security posture with no known vulnerabilities or CVEs. The static analysis reveals a remarkably small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, indicating the plugin likely performs a very specific, limited function without significant user interaction points. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are common sources of vulnerabilities. However, a significant concern arises from the presence of the 'create_function' dangerous function. While taint analysis shows no unsanitized paths, the use of 'create_function' is inherently risky as it can be exploited for code injection if its arguments are not rigorously sanitized. Additionally, only 20% of output is properly escaped, leaving the remaining 80% potentially vulnerable to cross-site scripting (XSS) attacks if dynamic content is being displayed.
Key Concerns
- Dangerous function create_function used
- Low output escaping percentage (20%)
- No capability checks on entry points
- No nonce checks on entry points
Show Content Only Security Vulnerabilities
Show Content Only Code Analysis
Dangerous Functions Found
Output Escaping
Show Content Only Attack Surface
WordPress Hooks 3
Maintenance & Trust
Show Content Only Maintenance & Trust
Maintenance Signals
Community Trust
Show Content Only Alternatives
Truncate Text
truncate-text
Truncate Text lets you shorten long strings of text in posts, pages, or custom content.
Advanced Excerpt
advanced-excerpt
Control the appearance of WordPress post excerpts
Toggle wpautop
toggle-wpautop
Easily disable the default wpautop filter on a post by post basis.
Advanced Rich Text Tools for Gutenberg
advanced-rich-text-tools
Additional tools for rich text fields in Gutenberg.
Trinity Audio – Text to Speech AI audio player to convert content into audio
trinity-audio
The audio player will convert your content into audio in just a few clicks, with one-time seamless integration (no support, or special tech knowledge …
Show Content Only Developer Profile
23 plugins · 14K total installs
How We Detect Show Content Only
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
button-small