Simple Content Adder Security & Risk Analysis

wordpress.org/plugins/simple-content-adder

Add custom content to your posts, pages and/or footer, without the need to update each post or page.

20 active installs v1.0 PHP + WP 4.0+ Updated Sep 29, 2016
add-content-above-postadd-content-below-postadd-content-footeradd-text-above-postadd-text-footer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Content Adder Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Content Adder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "simple-content-adder" plugin v1.0 exhibits a generally positive security posture in terms of its attack surface and vulnerability history. The absence of any recorded CVEs and the static analysis showing zero AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a strong indicator of good security practice.

However, the static analysis does reveal a significant concern regarding output escaping. With three total outputs analyzed and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is not properly sanitized and escaped before being displayed on the frontend or backend is a potential vector for malicious script injection. While there are no recorded vulnerabilities, this oversight in output handling is a critical weakness that could be exploited.

Overall, the plugin benefits from a minimal attack surface and a clean vulnerability history. The primary area of concern, and a point of significant risk, lies in the complete lack of output escaping. Addressing this would greatly improve the plugin's security. Until then, users should be cautious if the plugin handles any dynamic content that originates from user input.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

Simple Content Adder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple Content Adder Release Timeline

v1.0Current
Code Analysis
Analyzed Mar 16, 2026

Simple Content Adder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

0% escaped3 total outputs
Attack Surface

Simple Content Adder Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitcpt\sca-fields.php:5
filtermanage_edit-sca_content_columnssimple-content-adder.php:30
filtermanage_sca_content_posts_custom_columnsimple-content-adder.php:34
filteracf/settings/pathsimple-content-adder.php:38
filteracf/settings/dirsimple-content-adder.php:39
filteracf/settings/show_adminsimple-content-adder.php:40
actionadmin_menusimple-content-adder.php:45
actionadmin_enqueue_scriptssimple-content-adder.php:49
filterthe_contentsimple-content-adder.php:53
actionwp_footersimple-content-adder.php:57
Maintenance & Trust

Simple Content Adder Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedSep 29, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Alternatives

Simple Content Adder Alternatives

No alternatives data available yet.

Developer Profile

Simple Content Adder Developer Profile

Blaz K.

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Content Adder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-content-adder/css/simple-content-adder.css/wp-content/plugins/simple-content-adder/js/simple-content-adder.js
Script Paths
/wp-content/plugins/simple-content-adder/lib/advanced-custom-fields/acf.php

HTML / DOM Fingerprints

CSS Classes
sca_content
Data Attributes
data-sca-includedata-sca-positiondata-sca-class
JS Globals
window.jQuery
FAQ

Frequently Asked Questions about Simple Content Adder