
wp show category posts Security & Risk Analysis
wordpress.org/plugins/wp-show-category-postswp show category posts show's posts from any category
Is wp show category posts Safe to Use in 2026?
Generally Safe
Score 85/100wp show category posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-show-category-posts" plugin version 0.1 exhibits a mixed security posture. On the positive side, the absence of known CVEs and a history of no recorded vulnerabilities suggest a relatively stable past. The code analysis also indicates a lack of dangerous functions, no file operations, and no external HTTP requests, all of which are good security practices. Furthermore, all SQL queries are reported to use prepared statements, which significantly mitigates SQL injection risks.
However, several concerning aspects are present. The most significant is the complete lack of output escaping, with 0% of the 7 total outputs being properly escaped. This opens the door to Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the site's content via the plugin's output. Additionally, the absence of nonce checks and capability checks means that the plugin's functionality, even if it doesn't have explicitly dangerous functions, might be callable by unauthenticated or unauthorized users, potentially leading to unintended actions or information disclosure if the shortcode's output is manipulated.
The static analysis shows a small attack surface primarily consisting of one shortcode, with no unprotected entry points identified. However, the lack of proper escaping and authorization checks on its output and potential execution path represent the primary security weaknesses. The 0 taint flows analyzed is also a neutral factor, not providing further insight into potential data manipulation risks.
Key Concerns
- All outputs are unescaped
- Missing nonce checks
- Missing capability checks
wp show category posts Security Vulnerabilities
wp show category posts Code Analysis
Output Escaping
wp show category posts Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
wp show category posts Maintenance & Trust
Maintenance Signals
Community Trust
wp show category posts Alternatives
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Post Types Order
post-types-order
Sort posts and custom post type objects using a drag-and-drop, sortable JavaScript AJAX interface, or through the default WordPress dashboard
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Duplicate Post
copy-delete-posts
Duplicate post
wp show category posts Developer Profile
4 plugins · 250 total installs
How We Detect wp show category posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-show-category-posts/css/styles.csswp-show-category-posts/css/styles.css?ver=HTML / DOM Fingerprints
wpscp_containerwpscp_img_boxwpscp_detailwp show category posts out put starts here by ajay sharmawpscp_thumbnail_enablewpscp_title_enablewpscp_date_enablewpscp_excerpt_enablewpscp_readmore_enablewpscp_nop+9 more[wpscp]