
WP Jerusalem Post Security & Risk Analysis
wordpress.org/plugins/wp-jerusalem-postStable 1.0.0 Stable tag: trunk License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html
Is WP Jerusalem Post Safe to Use in 2026?
Generally Safe
Score 85/100WP Jerusalem Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-jerusalem-post" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface, and crucially, all identified entry points are reported as protected. Furthermore, the code signals reveal no dangerous functions, no raw SQL queries (all are prepared), and no file operations or external HTTP requests, which are all positive indicators. The plugin also does not bundle any libraries, removing a potential source of vulnerabilities.
However, a notable concern arises from the output escaping. With 25 total outputs and only 20% properly escaped, this indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. While no taint analysis flows with unsanitized paths were found, the lack of comprehensive output escaping creates a risk where user-supplied data could be injected into the output without proper sanitization, leading to XSS attacks.
The vulnerability history is clean, with zero known CVEs. This, combined with the lack of identified issues in the code analysis (other than output escaping), suggests that the developers may be following good security practices. However, the lack of nonce checks and capability checks, while not directly leading to a deduction in this specific version due to the limited attack surface, would be significant concerns if the plugin's functionality were to expand and introduce more exposed entry points.
Key Concerns
- Low percentage of properly escaped output
WP Jerusalem Post Security Vulnerabilities
WP Jerusalem Post Code Analysis
Output Escaping
WP Jerusalem Post Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP Jerusalem Post Maintenance & Trust
Maintenance Signals
Community Trust
WP Jerusalem Post Alternatives
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
Pinterest for WooCommerce
pinterest-for-woocommerce
Get your products in front of Pinterest users searching for ideas and things to buy. Connect your WooCommerce store to make your catalog browsable.
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
custom-facebook-feed
Formerly "Custom Facebook Feed". Display completely customizable Facebook feeds of a Facebook page. Supports Facebook oEmbeds.
UserFeedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds
userfeedback-lite
Ultimate user feedback plugin to ask questions, surveys, polls, from your website in seconds
WP Jerusalem Post Developer Profile
4 plugins · 10K total installs
How We Detect WP Jerusalem Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-jerusalem-post/style.cssHTML / DOM Fingerprints
jerusalempost-feedjerusalempost-feed-jerusalempost-itemjerusalempost-item-