
WP Show Posts Security & Risk Analysis
wordpress.org/plugins/wp-show-postsAdd posts to your website from any post type using a simple shortcode.
Is WP Show Posts Safe to Use in 2026?
Generally Safe
Score 90/100WP Show Posts has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin wp-show-posts v1.1.6 demonstrates several good security practices, including 100% usage of prepared statements for SQL queries and a high percentage of properly escaped output. The static analysis reveals no critical or high severity taint flows, indicating robust input sanitization for the analyzed paths. The presence of nonce and capability checks on all identified entry points, including AJAX handlers and shortcodes, further contributes to a generally secure posture. However, a history of three medium severity CVEs, with the most recent one being on April 16, 2024, is a significant concern. These past vulnerabilities, including Improper Authorization and Cross-site Scripting, suggest potential recurring weaknesses in how user input is handled or how access control is implemented, even if current analysis shows no immediate exploitable flaws. While the current code analysis is positive, the historical vulnerability pattern warrants caution and suggests that the plugin may have had exploitable issues in the past that could potentially re-emerge with future updates or in different contexts.
Key Concerns
- Multiple medium severity CVEs in history
- Recent vulnerability (2024-04-16)
- 88% output escaping (12% not escaped)
WP Show Posts Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WP Show Posts <= 1.1.5 - Improper Authorization to Information Exposure
WP Show Posts <= 1.1.4 - Information Exposure
WP Show Posts <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Show Posts Code Analysis
Output Escaping
Data Flow Analysis
WP Show Posts Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 39
Maintenance & Trust
WP Show Posts Maintenance & Trust
Maintenance Signals
Community Trust
WP Show Posts Alternatives
Visual Portfolio, Photo Gallery & Post Grid
visual-portfolio
Modern photo gallery and portfolio plugin with advanced layouts editor. Clean gallery styles with powerful settings in the Gutenberg block.
Premium Portfolio Features for Phlox theme
auxin-portfolio
Showcase your projects beautifully in Phlox theme
WPZOOM Portfolio Lite – Filterable Portfolio Plugin
wpzoom-portfolio
Portfolio plugin for WordPress. Create filterable portfolio grids with masonry layouts and lightbox. Ideal for photographers, designers, agencies.
Video Gallery – YouTube Gallery, Vimeo, Video Portfolio, Image Portfolio and Image Gallery
gallery-videos
Gallery is a user-friendly plugin to display user or hashtag-based gallery feeds as a responsive customizable gallery.
PowerFolio – Portfolio & Image Gallery for Elementor
portfolio-elementor
A powerful portfolio and gallery plugin for WP, Elementor and Gutenberg. Create portfolio and image galleries in seconds using any page builder!
WP Show Posts Developer Profile
9 plugins · 890K total installs
How We Detect WP Show Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-show-posts/css/wp-show-posts.css/wp-content/plugins/wp-show-posts/css/wp-show-posts-min.csswp-show-posts/css/wp-show-posts.css?ver=wp-show-posts/css/wp-show-posts-min.css?ver=HTML / DOM Fingerprints
wpsp-itemwpsp-item-innerdata-wpsp-idwpsp_id