
Simple Custom Content Adder Security & Risk Analysis
wordpress.org/plugins/simple-custom-content-adderA simple plugin that enables you to add some custom content to all of your posts and/or pages.
Is Simple Custom Content Adder Safe to Use in 2026?
Generally Safe
Score 85/100Simple Custom Content Adder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'simple-custom-content-adder' plugin v1.1 exhibits a strong adherence to security best practices in several key areas, as evidenced by the static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points suggests a minimal attack surface. Furthermore, the lack of detected dangerous functions, file operations, external HTTP requests, and critical or high severity taint flows are positive indicators of a secure codebase. The plugin also benefits from a clean vulnerability history with no recorded CVEs.
However, significant concerns arise from the SQL query handling and output escaping practices. The static analysis reveals that 100% of the two detected SQL queries are not using prepared statements. This lack of sanitization for database interactions presents a substantial risk of SQL injection vulnerabilities, even if none have been actively detected in taint analysis. Similarly, with 100% of the nine output operations being improperly escaped, the plugin is highly susceptible to Cross-Site Scripting (XSS) attacks, allowing malicious scripts to be injected into the user's browser.
In conclusion, while the plugin's limited attack surface and clean vulnerability history are commendable, the identified weaknesses in SQL query sanitization and output escaping are critical security flaws. These issues, if exploited, could lead to severe data breaches and site compromise. The presence of capability checks is a positive, but it does not mitigate the risks posed by the raw SQL queries and unescaped output.
Key Concerns
- SQL queries not using prepared statements (2/2)
- Output escaping is not properly implemented (9/9)
Simple Custom Content Adder Security Vulnerabilities
Simple Custom Content Adder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Simple Custom Content Adder Attack Surface
WordPress Hooks 3
Maintenance & Trust
Simple Custom Content Adder Maintenance & Trust
Maintenance Signals
Community Trust
Simple Custom Content Adder Alternatives
Essential Content Types
essential-content-types
Essential Content Types allows you to feature the impressive content through different content/post types on your website just the way you want it.
WP Post Disclaimer
wp-post-disclaimer
Add customizable disclaimers, terms, or warnings to the top, bottom, or within post, page, or custom post type content for WordPress
Disclaimer Popup
disclaimer-popup
Disclaimer Popup is a free plugin that will help you to quickly create a disclaimer popup complete with texts and images
Jetpack Without Promotions
hide-jetpack-promotions
Removes all admin notices for promotions added by Jetpack.
Woobox
woobox
Easily embed your Woobox promotions in WordPress using a simple shortcode.
Simple Custom Content Adder Developer Profile
3 plugins · 40K total installs
How We Detect Simple Custom Content Adder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-custom-content-adder/js/scca.js/wp-content/plugins/simple-custom-content-adder/js/scca.jssimple-custom-content-adder/js/scca.js?ver=HTML / DOM Fingerprints
id="scca_content"name="scca_content"id="scca_background_color"name="scca_background_color"id="scca_font_color"name="scca_font_color"+14 morescca_activatescca_menuscca_add_scriptsscca_settingsget_scca_css