
WP Query Creator Security & Risk Analysis
wordpress.org/plugins/wp-query-creatorWP Query Creator provides an interface for creating WP queries as shortcodes.
Is WP Query Creator Safe to Use in 2026?
Mostly Safe
Score 71/100WP Query Creator is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The wp-query-creator plugin version 1.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of output escaping. It also has a relatively small attack surface with only one shortcode and no direct AJAX handlers, REST API routes, or cron events that are exposed without authentication. However, significant concerns arise from its vulnerability history, specifically one unpatched medium severity CVE related to Cross-site Scripting. Furthermore, the static analysis reveals that 100% of the analyzed taint flows have unsanitized paths, which, although not categorized as critical or high severity in this specific analysis, points to a potential weakness in input sanitization that could be exploited in conjunction with other vulnerabilities or future code changes.
Key Concerns
- Unpatched medium CVE
- Taint flows with unsanitized paths (2/2)
- Missing nonce checks
- Missing capability checks
WP Query Creator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Query Creator <= 1.0 - Reflected Cross-Site Scripting
WP Query Creator Code Analysis
Output Escaping
Data Flow Analysis
WP Query Creator Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
WP Query Creator Maintenance & Trust
Maintenance Signals
Community Trust
WP Query Creator Alternatives
Advanced Query Loop
advanced-query-loop
Transform your Query Loop blocks into powerful, flexible content engines! 🚀
Loops & Logic
tangible-loops-and-logic
Loops & Logic is a template system with content loops and conditions.
Query Wrangler
query-wrangler
Query Wrangler provides an intuitive interface for creating complex WP queries as shortcodes and widgets. UI based on Drupal Views.
Query Loop Load More
query-loop-load-more
This WordPress plugin adds a load more option to the Query Loop Pagination block in Gutenberg, allowing users to load more posts without refreshing th …
Query Loop Post Selector
query-loop-post-selector
A native query loop extension that adds a new option in the filter that allows user to specifically pick certain posts to display
WP Query Creator Developer Profile
2 plugins · 380 total installs
How We Detect WP Query Creator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-query-creator/includes/css_js.phpHTML / DOM Fingerprints
boximagecontenttitledateexcerptreadmore<div class="box"><img class="image" src="%feature_img|thumbnail%"><div class="content"><h2 class="title">%title%</h2>