
Contributors: tradesouthwestgmailcom Security & Risk Analysis
wordpress.org/plugins/tsw-custom-listingTSW custom Listing makes a post type file available for using in Larrys List theme as a custom post type for posting listings to the theme.
Is Contributors: tradesouthwestgmailcom Safe to Use in 2026?
Generally Safe
Score 85/100Contributors: tradesouthwestgmailcom has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of tsw-custom-listing v1.1.12 reveals a plugin with a seemingly low attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the number of potential entry points for attackers. The code also shows a positive sign with all SQL queries utilizing prepared statements, indicating an effort to prevent SQL injection vulnerabilities. Furthermore, the absence of dangerous functions and file operations is encouraging.
However, a critical concern arises from the complete lack of output escaping. This means that any data displayed to users could potentially be manipulated by an attacker, leading to cross-site scripting (XSS) vulnerabilities. While taint analysis showed no unsanitized paths, the lack of output escaping is a blind spot that could allow for XSS if data is not handled correctly elsewhere in the plugin's logic. The vulnerability history being clean is a positive indicator, suggesting the plugin has not historically been a target or source of major security flaws, but this does not negate the immediate risks identified in the code analysis.
In conclusion, the plugin demonstrates good practices in preventing SQL injection and minimizing its attack surface. The primary weakness lies in its complete failure to escape output, presenting a significant risk of XSS vulnerabilities. The absence of any recorded vulnerabilities historically is good, but the current static analysis findings highlight areas that require immediate attention to improve the plugin's overall security posture.
Key Concerns
- No output escaping implemented
Contributors: tradesouthwestgmailcom Security Vulnerabilities
Contributors: tradesouthwestgmailcom Code Analysis
Output Escaping
Contributors: tradesouthwestgmailcom Attack Surface
WordPress Hooks 10
Maintenance & Trust
Contributors: tradesouthwestgmailcom Maintenance & Trust
Maintenance Signals
Community Trust
Contributors: tradesouthwestgmailcom Alternatives
Bulk Convert Post Format
bulk-convert-post-format
Bulk convert posts in a category to a selected post format.
IFTTT Post Formats & Post Types
ifttt-post-formats
Set a post format or post type for your IFTTT-created posts via a post format or post type category.
ytSubscribe – Youtube Subscribe Button
ytsubscribe
Automatically Add Youtube Subscribe Button Below each Video WordPress Plugin
Better Formats
better-formats
Improves the UI for WordPress's built-in post formats.
Easy News Ticker
easy-news-ticker
Easy news ticker is a tiny news ticker plugin that scroll the list infinitely vertically.
Contributors: tradesouthwestgmailcom Developer Profile
17 plugins · 2K total installs
How We Detect Contributors: tradesouthwestgmailcom
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tsw-custom-listing/icon_pin24.png/wp-content/plugins/tsw-custom-listing/custom-login-logo.pngHTML / DOM Fingerprints
Copyright 2014 Tradesouthwest (email : larry@tradesouthwest.com)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 3, aspublished by the Free Software Foundation.+14 moredata-post_type="listing"window.current_userwindow.current_user.user_loginwindow.author_posts