
ST Insert Post Security & Risk Analysis
wordpress.org/plugins/st-insert-post-pluginA simple front end post form for all users, and as a bonus the ability to list subpages.
Is ST Insert Post Safe to Use in 2026?
Generally Safe
Score 85/100ST Insert Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The st-insert-post-plugin v1.0.3 exhibits a strong security posture based on the provided static analysis. The complete absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and a lack of critical or high severity taint flows are excellent indicators of secure coding practices. Furthermore, the plugin's vulnerability history is clean, with no recorded CVEs, suggesting a well-maintained and secure codebase over time.
However, there are some areas that warrant attention. The plugin has two shortcodes, which represent entry points into the plugin's functionality. While the static analysis indicates no authentication or permission checks are associated with these entry points, and no unsanitized taint flows were found, the presence of entry points without explicit security checks is a potential concern. The absence of nonce checks and capability checks, as reported, could be a weakness if the shortcodes perform any sensitive operations or if they can be leveraged in conjunction with other vulnerabilities to execute actions without proper authorization. Despite these minor concerns, the overall security of this plugin appears to be good, with a strong emphasis on secure coding standards and a clean vulnerability history.
Key Concerns
- Shortcodes without capability checks
- Shortcodes without nonce checks
ST Insert Post Security Vulnerabilities
ST Insert Post Code Analysis
ST Insert Post Attack Surface
Shortcodes 2
WordPress Hooks 1
Maintenance & Trust
ST Insert Post Maintenance & Trust
Maintenance Signals
Community Trust
ST Insert Post Alternatives
ST Admin Protection
st-admin-protection
This plugin blocks everyone but the admin from accessing the Wordpresss Admin
amoForms
amoforms
Create forms and manage submissions easily with a simple interface. Contact forms, subscription forms, or other forms for WordPress. Absolutely FREE!
Blue Login Style
blue-login-style
Blue Login Style is a tiny plugin which allows to customize your wp-login theme easily with a click.
Gravity Forms: Post Updates
gravity-forms-post-updates
Allows you to use Gravity Forms to update any post on the front end.
Better Formats
better-formats
Improves the UI for WordPress's built-in post formats.
ST Insert Post Developer Profile
2 plugins · 20 total installs
How We Detect ST Insert Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/st-insert-post-plugin/css/style.cssst-insert-post-plugin/css/style.css?ver=HTML / DOM Fingerprints
st-insert-poststip-formstip-boxstip-labelstip-errorstip-successstls_listname="category"name="title"name="content"name="save"id="stip-message"class="stip-error"+2 morejavascript:history.go(-1)location.href[st_insert_post][stls]