
xili Post in Post Security & Risk Analysis
wordpress.org/plugins/xili-postinpostxili-postinpost provides a triple toolkit to insert post(s) everywhere in webpage. Template tag function, shortcode and widget are available.
Is xili Post in Post Safe to Use in 2026?
Generally Safe
Score 85/100xili Post in Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The xili-postinpost plugin v1.7.02 exhibits a generally good security posture based on the provided static analysis. It has no recorded vulnerabilities, no dangerous functions used, and all SQL queries utilize prepared statements, which are strong indicators of secure coding practices. The presence of nonce and capability checks, along with a low number of entry points, further contributes to its secure foundation. However, a significant concern arises from the output escaping analysis, where only 57% of outputs are properly escaped. This means that a substantial portion of the plugin's output might be vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not handled carefully within the unescaped portions of the code. While the attack surface is small and appears protected, the unescaped output represents a potential risk that warrants attention.
The lack of any recorded CVEs, unpatched vulnerabilities, or common vulnerability types in its history is a very positive sign. This suggests that the plugin has historically been maintained with security in mind, or has simply not been a target for significant exploits. Coupled with the absence of critical or high severity taint flows, this historical data reinforces the perception of a relatively safe plugin. However, the static analysis does highlight a weakness in output sanitization. The plugin's strengths lie in its foundational security practices like prepared SQL statements and the limited, authenticated attack surface. The main weakness is the potential for XSS vulnerabilities due to insufficient output escaping.
Key Concerns
- Insufficient output escaping (57% proper)
xili Post in Post Security Vulnerabilities
xili Post in Post Code Analysis
Output Escaping
xili Post in Post Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
xili Post in Post Maintenance & Trust
Maintenance Signals
Community Trust
xili Post in Post Alternatives
Compact Admin
compact-admin
Compact Admin simply makes the posts and pages lists in the admin pages more compact.
FS Link Posts
fs-link-posts
FS Link Posts is a simple plugin to enable you to manually associate a post with other posts you’ve created.
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
Duplicate Post
copy-delete-posts
Duplicate post
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
custom-facebook-feed
Formerly "Custom Facebook Feed". Display completely customizable Facebook feeds of a Facebook page. Supports Facebook oEmbeds.
xili Post in Post Developer Profile
4 plugins · 2K total installs
How We Detect xili Post in Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xili-postinpost/css/xili-postinpost.css/wp-content/plugins/xili-postinpost/js/xili-postinpost.jsxili-postinpost/css/xili-postinpost.css?ver=xili-postinpost/js/xili-postinpost.js?ver=HTML / DOM Fingerprints
xi_postinpostxi_postinpost_titlexi_postinpost_excerptxi_postinpost_content---------- function post in post or everywhere ---------- 080629 101006 -----cache used in same page because query called more than one timesave current loopsave current pagination vars used in wp_link_pages+1 moredata-moredata-featuredimagesizedata-featuredimageaslinkdata-featuredimagedata-nopostdata-lang+21 moreXili_Postinpostxili_postinpost_widget<div class="xi_postinpost"><h4 class="xi_postinpost_title"><object class="xi_postinpost_excerpt"><object class="xi_postinpost_content">