Advance Category Posts Widget Security & Risk Analysis

wordpress.org/plugins/advance-category-posts-widget

Provides a smart widget that shows posts from the selected category using tons of options.

80 active installs v1.0.1 PHP + WP 4.0+ Updated Apr 24, 2019
durationpostpost-durationpost-sliderpost-category
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Advance Category Posts Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Advance Category Posts Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of "advance-category-posts-widget" v1.0.1 reveals a generally strong security posture in several key areas. The plugin has no detected AJAX handlers, REST API routes, shortcodes, or cron events, resulting in zero identified entry points. Furthermore, it avoids dangerous functions, file operations, and external HTTP requests. The reliance on prepared statements for all SQL queries and the absence of any recorded vulnerabilities, including CVEs, are significant strengths. However, a notable concern is the relatively low rate of output escaping, with only 68% of outputs being properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care before being displayed. The complete lack of nonce checks and capability checks on any potential (though currently non-existent) entry points means that if entry points were to be introduced in future versions without proper security measures, they would be immediately vulnerable.

Key Concerns

  • Low output escaping rate
  • No nonce checks on potential entry points
  • No capability checks on potential entry points
Vulnerabilities
None known

Advance Category Posts Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Advance Category Posts Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
63 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

68% escaped92 total outputs
Attack Surface

Advance Category Posts Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_enqueue_scriptsassets.php:11
actionadmin_enqueue_scriptsassets.php:12
actionwidgets_initinit.php:6
Maintenance & Trust

Advance Category Posts Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedApr 24, 2019
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

Advance Category Posts Widget Developer Profile

saurav.rox

4 plugins · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advance Category Posts Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advance-category-posts-widget/assets/front.css/wp-content/plugins/advance-category-posts-widget/assets/owl.carousel.min.css/wp-content/plugins/advance-category-posts-widget/assets/custom.js/wp-content/plugins/advance-category-posts-widget/assets/custom.css
Script Paths
/wp-content/plugins/advance-category-posts-widget/assets/owl.carousel.min.js/wp-content/plugins/advance-category-posts-widget/assets/custom.js
Version Parameters
advance-category-posts-widget/assets/front.css?ver=advance-category-posts-widget/assets/owl.carousel.min.css?ver=advance-category-posts-widget/assets/owl.carousel.min.js?ver=advance-category-posts-widget/assets/custom.js?ver=advance-category-posts-widget/assets/custom.css?ver=

HTML / DOM Fingerprints

CSS Classes
apcw-custom-class
FAQ

Frequently Asked Questions about Advance Category Posts Widget