AC Simple Post Widget Security & Risk Analysis

wordpress.org/plugins/ac-simple-post-widget

Provide both widgets and shortcode to help you display your post on your website.

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Sep 19, 2015
custom-post-typefeatured-imageshortocdewidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AC Simple Post Widget Safe to Use in 2026?

Generally Safe

Score 85/100

AC Simple Post Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'ac-simple-post-widget' plugin, version 1.0.0, presents a mixed security posture. On the positive side, the plugin exhibits a lack of known CVEs and no recorded vulnerabilities, suggesting a potentially stable and secure history. Furthermore, the absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are strong indicators of good development practices. The static analysis also reveals no critical or high-severity taint flows, which is a significant positive. However, there are notable concerns. A significant portion of output is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if the shortcode handles user-provided or dynamic content. Additionally, the lack of nonce checks and capability checks on the identified shortcode leaves it potentially open to unauthorized access or execution, depending on the shortcode's functionality. While the attack surface is small (one shortcode), the absence of these critical security measures on this entry point is a weakness.

Key Concerns

  • Unescaped output detected
  • Missing nonce check on shortcode
  • Missing capability check on shortcode
Vulnerabilities
None known

AC Simple Post Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AC Simple Post Widget Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

AC Simple Post Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
30
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped30 total outputs
Attack Surface

AC Simple Post Widget Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ac_spw] acsimplepostwidget.php:234
WordPress Hooks 4
actionwidgets_initacsimplepostwidget.php:192
actionadmin_headacsimplepostwidget.php:241
actionwp_enqueue_scriptsacsimplepostwidget.php:249
filterexcerpt_lengthacsimplepostwidget.php:254
Maintenance & Trust

AC Simple Post Widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedSep 19, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

AC Simple Post Widget Developer Profile

aaron_carmen

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AC Simple Post Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ac-simple-post-widget/css/acsimplepostwidget.css/wp-content/plugins/ac-simple-post-widget/js/acsimplepostwidget.js
Script Paths
/wp-content/plugins/ac-simple-post-widget/js/acsimplepostwidget.js
Version Parameters
acsimplepostwidget/css/acsimplepostwidget.css?ver=acsimplepostwidget/js/acsimplepostwidget.js?ver=

HTML / DOM Fingerprints

CSS Classes
ac_widget_ulac_border_bottomac_featured_imgac_post_containerac_post_titleac_post_excerpt
Data Attributes
target="_blank"
Shortcode Output
[ac_spw]
FAQ

Frequently Asked Questions about AC Simple Post Widget