The Insertr Security & Risk Analysis

wordpress.org/plugins/the-insertr

WordPress dynamic keyword insertion plugin.

20 active installs v1.6.0 PHP 8.2.0+ WP 6.3+ Updated Mar 5, 2026
ad-manageradsdynamic-insertiondynamic-keyword-insertionkeyword
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is The Insertr Safe to Use in 2026?

Generally Safe

Score 100/100

The Insertr has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "the-insertr" v1.6.0 demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and output escaping issues are significant strengths. Furthermore, the plugin has no recorded vulnerabilities, which suggests a history of secure development or diligent patching by users.

However, a notable concern arises from the lack of nonce and capability checks across its entry points, including the single shortcode. While the static analysis reported zero unprotected entry points, this is likely due to the limited attack surface. The absence of these fundamental security checks creates a potential blind spot. If the shortcode were to interact with user-supplied data or perform sensitive actions, this lack of validation could be exploited. The lack of taint analysis results is also inconclusive, but given the absence of other high-risk indicators, it doesn't currently present a specific threat.

In conclusion, "the-insertr" v1.6.0 is generally well-developed from a security perspective, with a clean vulnerability history and good practices in key areas like SQL and output handling. The primary area for improvement and potential risk lies in the implementation of proper authorization and validation mechanisms for its shortcode to ensure it remains secure even as its functionality potentially evolves or is used in diverse environments.

Key Concerns

  • Missing nonce checks on shortcode
  • Missing capability checks on shortcode
Vulnerabilities
None known

The Insertr Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

The Insertr Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

The Insertr Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[insertr] the-insertr.php:93
WordPress Hooks 10
filteracf/load_value/type=shortcodethe-insertr.php:127
filterwpseo_titlethe-insertr.php:138
filterwpseo_metadescthe-insertr.php:141
filterrank_math/frontend/titlethe-insertr.php:148
filterrank_math/frontend/descriptionthe-insertr.php:151
filteraioseo_titlethe-insertr.php:158
filteraioseo_descriptionthe-insertr.php:161
filterseopress_titles_titlethe-insertr.php:168
filterseopress_titles_descthe-insertr.php:171
actioninitthe-insertr.php:214
Maintenance & Trust

The Insertr Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 5, 2026
PHP min version8.2.0
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

The Insertr Developer Profile

garethmorgans

3 plugins · 30 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect The Insertr

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/the-insertr/build/insertr-block.js
Script Paths
/wp-content/plugins/the-insertr/build/insertr-block.js
Version Parameters
the-insertr/build/insertr-block.js?ver=

HTML / DOM Fingerprints

Shortcode Output
[insertr key="" fallback="" case=""]
FAQ

Frequently Asked Questions about The Insertr