
WP Post Disclaimer Security & Risk Analysis
wordpress.org/plugins/wp-post-disclaimerAdd customizable disclaimers, terms, or warnings to the top, bottom, or within post, page, or custom post type content for WordPress
Is WP Post Disclaimer Safe to Use in 2026?
Generally Safe
Score 92/100WP Post Disclaimer has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-post-disclaimer plugin version 1.0.4 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong positive indicator. Furthermore, the presence of nonce and capability checks, along with a high percentage of properly escaped output, suggests adherence to secure coding practices for input handling and output rendering. The limited attack surface, with no unprotected entry points, further reinforces this assessment.
However, the plugin does have a known medium severity Cross-Site Scripting (XSS) vulnerability in its history, which was last patched on March 25, 2024. While currently unpatched CVEs are zero, this past vulnerability indicates that improper neutralization of input during web page generation has been an issue in the past. The taint analysis, while showing no current unsanitized flows, does not negate the potential for such issues to arise if input handling is not meticulously maintained. The fact that a vulnerability was identified and patched means that past versions were susceptible, and a diligent approach to ongoing security is necessary.
In conclusion, the plugin demonstrates a good foundation of secure coding, with minimal immediate risks identified in the static analysis. The primary area of caution stems from its past XSS vulnerability, underscoring the importance of continued vigilance and ensuring that all input is handled with care. The plugin is likely safe to use, assuming the latest patched version is installed and that the past vulnerability was indeed addressed.
Key Concerns
- Past medium severity XSS vulnerability
WP Post Disclaimer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Post Disclaimer <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Post Disclaimer Code Analysis
Output Escaping
WP Post Disclaimer Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
WP Post Disclaimer Maintenance & Trust
Maintenance Signals
Community Trust
WP Post Disclaimer Alternatives
Cart Notices for WooCommerce
cart-notices-for-woocommerce
Display on cart page notices based on products and product categories in cart, cart cost, current day and time, customer referrer.
WP BrowserUpdate
wp-browser-update
This plugin notifies website visitors to update their outdated browser in a non-intrusive way.
Product Notices for WooCommerce
product-notices-for-woocommerce
Make the best of product announcements, promos, discounts, alerts, etc. on your eCommerce site with this one of its kind WooCommerce extension.
Admin Notice
admin-notice
Display a custom notice to all users in the WordPress admin.
Banner Alerts
banner-alerts
Provides an easy interface for creating and displaying alerts or notices as a banner on a website
WP Post Disclaimer Developer Profile
1 plugin · 2K total installs
How We Detect WP Post Disclaimer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-post-disclaimer/assets/css/fontawesome/all.min.css/wp-content/plugins/wp-post-disclaimer/assets/css/fontawesome/all.csswp-post-disclaimer/assets/css/fontawesome/all.min.css?ver=wp-post-disclaimer/assets/css/fontawesome/all.css?ver=HTML / DOM Fingerprints
wppd-disclaimer-wrapwppd-title-wrapwppd-content-wrap<!-- WP Post Disclaimer Settings --><!-- WP Post Disclaimer Metabox --><!-- WP Post Disclaimer -->data-wppd-optionsdata-wppd-contentdata-wppd-titlewppd_options[wppd_disclaimer][wppd_disclaimer title="My Custom Title"]