
Simple Content Templates for Blog Posts & Pages Security & Risk Analysis
wordpress.org/plugins/simple-post-templateCreate content templates for your posts and pages. When creating a new post or page use one of your content templates as the starting point!
Is Simple Content Templates for Blog Posts & Pages Safe to Use in 2026?
Mostly Safe
Score 78/100Simple Content Templates for Blog Posts & Pages is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "simple-post-template" plugin v2.2.7 exhibits a mixed security posture. On the positive side, static analysis reveals a robust implementation regarding output escaping, with 100% of outputs properly sanitized. Furthermore, the plugin demonstrates good practices by implementing nonce checks and capability checks for its internal operations. The absence of file operations, external HTTP requests, and a zero-width attack surface from AJAX, REST API, and shortcodes are also strong security indicators.
However, significant concerns arise from the vulnerability history and the handling of SQL queries. The presence of one unpatched medium-severity CVE, historically identified as Cross-Site Request Forgery (CSRF), poses an immediate risk. This, combined with the fact that 100% of the four detected SQL queries are not using prepared statements, creates a vulnerability profile that requires attention. The lack of prepared statements in SQL queries, while not explicitly detailed as an exploit in the static analysis, can often be a precursor to SQL injection vulnerabilities if user input is not meticulously handled, even with output escaping in place for other contexts.
In conclusion, while the plugin has made good efforts in sanitizing output and limiting its direct attack surface, the unpatched historical vulnerability and the prevalent use of raw SQL queries represent significant weaknesses. The historical CSRF vulnerability, if not addressed, remains a serious threat, and the lack of prepared statements for SQL queries introduces potential risks that should be mitigated to improve the overall security of the plugin.
Key Concerns
- Unpatched medium CVE
- Raw SQL queries without prepared statements
Simple Content Templates for Blog Posts & Pages Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Content Templates for Blog Posts & Pages <= 2.2.61 - Cross-Site Request Forgery
Simple Content Templates for Blog Posts & Pages Code Analysis
SQL Query Safety
Output Escaping
Simple Content Templates for Blog Posts & Pages Attack Surface
WordPress Hooks 11
Maintenance & Trust
Simple Content Templates for Blog Posts & Pages Maintenance & Trust
Maintenance Signals
Community Trust
Simple Content Templates for Blog Posts & Pages Alternatives
Yoast Duplicate Post
duplicate-post
The go-to tool for cloning posts and pages, including the powerful Rewrite & Republish feature.
WP Duplicate Page
wp-duplicate-page
Clone WordPress page, post, custom post types
Clone Posts
clone-posts
Easily clone (duplicate) Posts, Pages and Custom Post Types, including their custom fields (post_meta)
Export Themes
wp-clone-template
With this plugin you'll be able to export your themes in a .zip file and then install with that .zip file the same theme in other servers using t …
Duplicate Post by AIOSEO – Easily Clone and Republish Content
duplicate-post-page-aioseo
Duplicate Post by AIOSEO lets you clone and schedule revisions for your posts & pages with just one click.
Simple Content Templates for Blog Posts & Pages Developer Profile
7 plugins · 6K total installs
How We Detect Simple Content Templates for Blog Posts & Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-post-template/admin/css/advanced-content-templates-admin.css/wp-content/plugins/simple-post-template/admin/js/advanced-content-templates-admin.js/wp-content/plugins/simple-post-template/admin/js/advanced-content-templates-admin.jssimple-post-template/admin/css/advanced-content-templates-admin.css?ver=simple-post-template/admin/js/advanced-content-templates-admin.js?ver=HTML / DOM Fingerprints
sct-settingssct-upgradePrevent direct accessThis function is provided for demonstration purposes only.data-editor-contentdata-content-template-idwindow.simpleContentTemplates