
WP-SNAP! Security & Risk Analysis
wordpress.org/plugins/wp-snapWP-SNAP! (WordPress System for Navigating Alphabetized Posts) creates an user interface for navigating alphabetized post titles.
Is WP-SNAP! Safe to Use in 2026?
Generally Safe
Score 85/100WP-SNAP! has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-snap" v0.9.4 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points, combined with the presence of nonce and capability checks, suggests a well-defined and secured attack surface. Furthermore, the fact that all SQL queries utilize prepared statements is a significant strength, mitigating common SQL injection risks. The plugin also shows no known historical vulnerabilities, indicating a consistent effort towards security or a lack of targeted analysis until now.
However, a critical concern arises from the output escaping. With 11 total outputs and 0% properly escaped, this presents a significant risk for Cross-Site Scripting (XSS) vulnerabilities. Any data outputted by the plugin, if not properly sanitized on input, could be injected with malicious scripts that would then execute in the user's browser. While taint analysis did not reveal any unsanitized paths, this could be an artifact of the limited analysis scope or the nature of the flows examined. The lack of file operations and external HTTP requests further contributes to a reduced risk profile in those specific areas.
In conclusion, "wp-snap" v0.9.4 has several commendable security practices, particularly in its handling of entry points and database queries. The primary weakness is the complete lack of output escaping, which is a serious deficiency that must be addressed to prevent XSS attacks. The clean vulnerability history is positive, but the identified output escaping issue overshadows this strength, necessitating immediate attention.
Key Concerns
- All output is unescaped
WP-SNAP! Security Vulnerabilities
WP-SNAP! Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-SNAP! Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP-SNAP! Maintenance & Trust
Maintenance Signals
Community Trust
WP-SNAP! Alternatives
Posts List
posts-list
Adds a posts (or pages) list of your blog pages (or posts) by entering the shortcode [posts-list].
Styles For WP Pagenavi Addon – Better design for post pagination
styles-for-wp-pagenavi-addon
Adds a more styling options to Wp-PageNavi WordPress plugin OR the_posts_pagination() WordPress navigation function.
IntelliWidget Per Page Custom Menus and Dynamic Content
intelliwidget-per-page-featured-posts-and-menus
Display custom menus, featured posts, custom post types and other dynamic content on a per page, per post or site-wide basis.
Admin Quick Jump
admin-quick-jump
Admin Quick Jump adds a dropdown list to the admin edit-post area. This allows you to quickly jump to other draft and published posts/pages.
WP Different Navigation on Each Page And Post
wp-different-navigation-on-each-page-and-post
This plugin are display different-different navigation on each page and post.You Can easily setup different navigation or menu on pages and single pos …
WP-SNAP! Developer Profile
1 plugin · 90 total installs
How We Detect WP-SNAP!
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-snap/wp-snap.css/wp-content/plugins/wp-snap/wp-snap.js/wp-content/plugins/wp-snap/wp-snap.jswp-snap/wp-snap.css?ver=wp-snap/wp-snap.js?ver=HTML / DOM Fingerprints
snap_navsnap_selecteddata-snap-navwp_snap_navwp_snap_vars[wp_snap][wp_snap_browse]