AB Show Thumbs On Post Security & Risk Analysis

wordpress.org/plugins/ab-show-thumbs-on-post

Plugin that show featured image on post list.

10 active installs v1.00 PHP + WP 3.8+ Updated Unknown
counterfeaturedpostview
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AB Show Thumbs On Post Safe to Use in 2026?

Generally Safe

Score 100/100

AB Show Thumbs On Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of the "ab-show-thumbs-on-post" plugin v1.00 reveals a plugin with a remarkably small attack surface, featuring no AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests suggests a limited scope of potential malicious interaction. The fact that all identified SQL queries utilize prepared statements is a strong security positive. However, a significant concern arises from the complete lack of output escaping for all identified output points. This means that any data displayed by the plugin, if not inherently sanitized, could be vulnerable to cross-site scripting (XSS) attacks. The plugin also lacks nonce and capability checks, which, while not directly exploitable due to the zero entry points, would be a critical deficiency if any entry points were to be introduced in future versions. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past security diligence or a lack of historical focus on this plugin by attackers. Overall, the plugin exhibits good practices in avoiding common attack vectors but has a critical flaw in output handling that requires immediate attention. The lack of entry points shields it from exploitation of this flaw currently, but this is a latent risk.

Key Concerns

  • Output not properly escaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

AB Show Thumbs On Post Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AB Show Thumbs On Post Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

AB Show Thumbs On Post Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filtermanage_posts_columnsab-show-thumbs-on-post-plugin.php:24
filtermanage_posts_custom_columnab-show-thumbs-on-post-plugin.php:25
Maintenance & Trust

AB Show Thumbs On Post Maintenance & Trust

Maintenance Signals

WordPress version tested4.95
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

AB Show Thumbs On Post Developer Profile

abjelosevic

4 plugins · 30 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AB Show Thumbs On Post

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about AB Show Thumbs On Post