
WP Indeed Post Security & Risk Analysis
wordpress.org/plugins/wp-infeed-postインフィード広告を挿入可能な新着記事表示プラグインです。
Is WP Indeed Post Safe to Use in 2026?
Generally Safe
Score 85/100WP Indeed Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-infeed-post plugin v1.0 exhibits a mixed security posture. On the positive side, it boasts a clean vulnerability history with no recorded CVEs, suggesting a generally well-maintained codebase. Furthermore, it effectively utilizes prepared statements for its SQL queries and includes nonce checks, demonstrating good practices in preventing common web attacks. The absence of file operations and external HTTP requests also reduces potential attack vectors.
However, there are significant concerns within the static analysis. A concerning 28% of output escaping is present, meaning a substantial portion of user-generated or dynamic content displayed to users is not properly sanitized. This could lead to Cross-Site Scripting (XSS) vulnerabilities if an attacker can inject malicious scripts that are then rendered without proper encoding. The taint analysis also reveals one flow with an unsanitized path, which, while not classified as critical or high severity, still represents a potential security weakness where data might be processed in an unexpected or insecure manner.
In conclusion, while the plugin's track record and SQL handling are strengths, the identified output escaping and taint flow issues present notable risks. The lack of capability checks on any entry points, combined with the absence of these checks on the identified unsanitized flow, further exacerbates the potential impact of the identified weaknesses. Mitigation of the unescaped output and unsanitized taint flow should be a priority.
Key Concerns
- Unsanitized output detected
- Unsanitized taint flow detected
- Missing capability checks on entry points
WP Indeed Post Security Vulnerabilities
WP Indeed Post Release Timeline
WP Indeed Post Code Analysis
Output Escaping
Data Flow Analysis
WP Indeed Post Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP Indeed Post Maintenance & Trust
Maintenance Signals
Community Trust
WP Indeed Post Alternatives
No alternatives data available yet.
WP Indeed Post Developer Profile
1 plugin · 10 total installs
How We Detect WP Indeed Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-infeed-post/style/wp-infeed-post.css/wp-content/plugins/wp-infeed-post/views/wp-infeed-post-options.php/wp-content/plugins/wp-infeed-post/views/wp-infeed-post-widget.phpHTML / DOM Fingerprints
id="setting-error-settings_updated"class="error settings-error notice is-dismissible"class="updated settings-error notice is-dismissible"name="wp_infeed_post_action"name="wp_infeed_post_field"my_title_sizemy_title_colormy_cat_colormy_cat_back_colormy_date_color