AB Show Thumbs On Post Security & Risk Analysis
wordpress.org/plugins/ab-show-thumbs-on-postPlugin that show featured image on post list.
Is AB Show Thumbs On Post Safe to Use in 2026?
Generally Safe
Score 100/100AB Show Thumbs On Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "ab-show-thumbs-on-post" plugin v1.00 reveals a plugin with a remarkably small attack surface, featuring no AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests suggests a limited scope of potential malicious interaction. The fact that all identified SQL queries utilize prepared statements is a strong security positive. However, a significant concern arises from the complete lack of output escaping for all identified output points. This means that any data displayed by the plugin, if not inherently sanitized, could be vulnerable to cross-site scripting (XSS) attacks. The plugin also lacks nonce and capability checks, which, while not directly exploitable due to the zero entry points, would be a critical deficiency if any entry points were to be introduced in future versions. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past security diligence or a lack of historical focus on this plugin by attackers. Overall, the plugin exhibits good practices in avoiding common attack vectors but has a critical flaw in output handling that requires immediate attention. The lack of entry points shields it from exploitation of this flaw currently, but this is a latent risk.
Key Concerns
- Output not properly escaped
- No nonce checks on entry points
- No capability checks on entry points
AB Show Thumbs On Post Security Vulnerabilities
AB Show Thumbs On Post Code Analysis
Output Escaping
AB Show Thumbs On Post Attack Surface
WordPress Hooks 2
Maintenance & Trust
AB Show Thumbs On Post Maintenance & Trust
Maintenance Signals
Community Trust
AB Show Thumbs On Post Alternatives
Post Views Counter
post-views-counter
Post Views Counter allows you to collect and display how many times a post, page, or other content has been viewed in a simple, fast and reliable way.
WP-PostViews
wp-postviews
Enables you to display how many times a post/page had been viewed.
Wp Post Views – WordPress Post views counter
wp-post-views
Wordpress Post views counter
Post View Count
wp-simple-post-view
Add a "Post View Count" plugin to get the count of views for your posts.
WP Views Counter
wpecounter
Fast, lightweight post views counter. Display views in admin, blocks or shortcodes — no tracking scripts required.
AB Show Thumbs On Post Developer Profile
4 plugins · 30 total installs
How We Detect AB Show Thumbs On Post
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.