
SuperCPT Security & Risk Analysis
wordpress.org/plugins/super-cptInsanely easy and attractive custom post types, custom post meta, and custom taxonomies
Is SuperCPT Safe to Use in 2026?
Generally Safe
Score 85/100SuperCPT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The super-cpt plugin version 0.2.1 exhibits a generally positive security posture based on the static analysis. There are no identified dangerous functions, file operations, or external HTTP requests, which significantly reduces the attack surface. The complete absence of raw SQL queries, with 100% of them using prepared statements, is a strong indicator of good database interaction practices. Furthermore, the presence of nonce and capability checks, even with a limited attack surface, suggests an attempt to implement basic access controls.
However, a significant concern arises from the extremely low percentage of properly escaped output (6%). This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied or dynamic data may be rendered directly in the browser without sufficient sanitization. The lack of identified taint flows might be due to the limited attack surface or the scope of the analysis, but the output escaping issue is a concrete and significant risk.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive sign, suggesting the developers may have a proactive approach to security or that the plugin has not yet been a target for in-depth vulnerability research. However, a clean history does not guarantee future security, especially given the identified output escaping weakness. The overall conclusion is that while the plugin avoids many common pitfalls, the severe lack of output escaping presents a substantial risk that requires immediate attention.
Key Concerns
- Low percentage of properly escaped output
SuperCPT Security Vulnerabilities
SuperCPT Code Analysis
Output Escaping
SuperCPT Attack Surface
WordPress Hooks 18
Maintenance & Trust
SuperCPT Maintenance & Trust
Maintenance Signals
Community Trust
SuperCPT Alternatives
KontrolWP – Kontrol WordPress Developer Kit
kontrolwp
KontrolWP is an advanced Wordpress plugin for developers. Easily create CMS sites using advanced custom fields, custom post types, SEO and more.
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
Sydney Toolbox
sydney-toolbox
Registers custom post types and custom fields for the Sydney theme
Custom Post Types and Custom Fields creator – WCK
wck-custom-fields-and-custom-post-types-creator
A must have tool for creating custom fields, custom post types and taxonomies, fast and without any programming knowledge.
SuperCPT Developer Profile
6 plugins · 8K total installs
How We Detect SuperCPT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/super-cpt/css/supercpt.css/wp-content/plugins/super-cpt/js/supercpt.js/wp-content/plugins/super-cpt/js/supercpt.jssupercpt.css?ver=0.2.0supercpt.js?ver=0.2.1