
Unlisted Posts Security & Risk Analysis
wordpress.org/plugins/unlisted-postsAllows you to easily exclude posts from feeds, category pages, blog pages and more using one checkbox on posts.
Is Unlisted Posts Safe to Use in 2026?
Generally Safe
Score 85/100Unlisted Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'unlisted-posts' plugin version 1.1.0 exhibits a strong security posture based on the provided static analysis. The absence of any detected entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly reduces the plugin's attack surface. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries (all use prepared statements), and no file operations or external HTTP requests, which are all positive indicators. The presence of nonce and capability checks, while only one each, suggests an awareness of basic security practices.
However, a critical concern emerges from the output escaping analysis. With one total output and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from user input or an insecure source could be exploited. The taint analysis showing zero flows is reassuring but doesn't negate the identified output escaping deficiency. The plugin's vulnerability history being completely clear is a positive sign of past security diligence, but it doesn't shield it from potential future vulnerabilities, especially given the identified output escaping issue.
In conclusion, while the plugin has a remarkably small attack surface and avoids common pitfalls like raw SQL and dangerous functions, the lack of proper output escaping is a significant weakness that could lead to severe security compromises. The strength lies in its minimal exposure, but the specific flaw in output handling demands immediate attention.
Key Concerns
- Unescaped output
Unlisted Posts Security Vulnerabilities
Unlisted Posts Code Analysis
Output Escaping
Unlisted Posts Attack Surface
WordPress Hooks 4
Maintenance & Trust
Unlisted Posts Maintenance & Trust
Maintenance Signals
Community Trust
Unlisted Posts Alternatives
Post Visibility Control
post-visibility-control
Control post visibility in archives and search results for all content types.
Hide Posts
whp-hide-posts
Allows you to hide any posts on the home page, category page, search page, tags page, authors page, RSS Feed, REST API, XML sitemaps, SEO integrations …
Page Cache & Visibility Manager for Fastest Cache
page-cache-visibility-manager-for-wp-fastest-cache
Select specific pages to exclude from Fastest Cache and/or hide from non-staff users with a simple settings page.
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets
widget-options
0ddcemmihs4a843ekhaoofzosrunf4bl Widget Options gives you super powers to control your site’s sidebar widgets and all Gutenberg blocks on pages, posts …
If Menu – Visibility control for Menus
if-menu
Display tailored menu items to each visitor with visibility rules
Unlisted Posts Developer Profile
5 plugins · 15K total installs
How We Detect Unlisted Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
misc-pub-sectionmisc-pub-section-lastname="_unlisted_post"name="unlisted_posts_nonce"id="unlisted-post-meta-box"