
Hide Posts Security & Risk Analysis
wordpress.org/plugins/whp-hide-postsAllows you to hide any posts on the home page, category page, search page, tags page, authors page, RSS Feed, REST API, XML sitemaps, SEO integrations …
Is Hide Posts Safe to Use in 2026?
Generally Safe
Score 100/100Hide Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'whp-hide-posts' plugin v2.1.0 exhibits a generally strong security posture, adhering to several good practices. The absence of known CVEs and a clean vulnerability history are positive indicators. The code analysis reveals a robust implementation of security measures, with a high percentage of SQL queries using prepared statements and proper output escaping. Nonce and capability checks are also present for its entry points.
However, the taint analysis highlights two flows with unsanitized paths, both classified as high severity. This is a significant concern, suggesting that user-supplied data might be used in a way that could lead to vulnerabilities, even though no specific exploitable issues were identified in this static analysis. The plugin's attack surface, while currently protected, could present future risks if new entry points are added without adequate security checks.
Overall, while the plugin has strengths in its current security implementations and a clean history, the identified high-severity taint flows warrant immediate attention and thorough investigation to ensure they do not lead to actual exploits. The development team should prioritize addressing these unsanitized paths.
Key Concerns
- High severity taint flows with unsanitized paths
- Minor portion of SQL queries not using prepared statements
- Minor portion of outputs not properly escaped
Hide Posts Security Vulnerabilities
Hide Posts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Hide Posts Attack Surface
AJAX Handlers 2
REST API Routes 2
WordPress Hooks 31
Maintenance & Trust
Hide Posts Maintenance & Trust
Maintenance Signals
Community Trust
Hide Posts Alternatives
WP-ShowHide
wp-showhide
Allows you to embed content within your blog post via WordPress ShortCode API and toggling the visibility of the content via a link.
Content Visibility for Divi Builder
content-visibility-for-divi-builder
Content Visibility for Divi Builder.
Unlisted Posts
unlisted-posts
Allows you to easily exclude posts from feeds, category pages, blog pages and more using one checkbox on posts.
Responsive Visibility for Blocks Editor (Hide/Show Blocks for Devices)
responsive-visibility
🌟 Enhance Your WordPress Site with Responsive Visibility for Gutenberg Blocks
Post Visibility Control
post-visibility-control
Control post visibility in archives and search results for all content types.
Hide Posts Developer Profile
3 plugins · 20K total installs
How We Detect Hide Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whp-hide-posts/assets/css/backend.css/wp-content/plugins/whp-hide-posts/assets/js/backend.js/wp-content/plugins/whp-hide-posts/assets/js/bulk-edit.js/wp-content/plugins/whp-hide-posts/assets/js/quick-edit.js/wp-content/plugins/whp-hide-posts/assets/js/frontend.jswhp-hide-posts/assets/css/backend.css?ver=whp-hide-posts/assets/js/backend.js?ver=whp-hide-posts/assets/js/bulk-edit.js?ver=whp-hide-posts/assets/js/quick-edit.js?ver=whp-hide-posts/assets/js/frontend.js?ver=HTML / DOM Fingerprints
whp-hide-post-wrapperwhp-hide-post-bulk-edit-wrapperwhp-hide-post-quick-edit-wrapperdata-whp-iddata-whp-meta-keywhp_varswhp_bulk_varswhp_quick_vars/wp-json/whp/v1/get-metas/wp-json/whp/v1/save-meta