Related Posts Widget with Thumbnails Security & Risk Analysis

wordpress.org/plugins/advanced-css3-related-posts-widget

Here is wonderful plugin for displaying links to related posts beneath each

100 active installs v1.2 PHP + WP 5.1+ Updated Oct 3, 2023
entriespagespostpostsrelated
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEMar 31, 2025
Safety Verdict

Is Related Posts Widget with Thumbnails Safe to Use in 2026?

Use With Caution

Score 64/100

Related Posts Widget with Thumbnails has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Mar 31, 2025Updated 2yr ago
Risk Assessment

The 'advanced-css3-related-posts-widget' plugin version 1.2 presents a mixed security posture. While the static analysis indicates a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, and all SQL queries utilize prepared statements, significant concerns arise from output escaping and the vulnerability history.

The code analysis reveals a very low rate of proper output escaping (4%), meaning a substantial portion of output is potentially vulnerable to cross-site scripting (XSS) attacks. The absence of capability checks and nonce checks on any potential entry points, though the number of entry points is zero, suggests a lack of robust security measures in place if any were to be introduced in future versions or if the static analysis missed something. The taint analysis showing no flows is a positive sign, but this could be due to a lack of complex data flows or incomplete analysis.

The plugin has a history of known vulnerabilities, with one medium-severity Cross-Site Request Forgery (CSRF) vulnerability currently unpatched. This indicates a recurring pattern of security weaknesses, specifically related to CSRF, and the fact that it remains unpatched is a significant concern. While the plugin demonstrates good practices in SQL query handling, the critical issues with output escaping and the unpatched CSRF vulnerability outweigh these strengths, necessitating caution.

Key Concerns

  • Unpatched CVE (Medium Severity)
  • Low output escaping percentage
  • No capability checks
  • No nonce checks
Vulnerabilities
1 published

Related Posts Widget with Thumbnails Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31570medium · 6.1Cross-Site Request Forgery (CSRF)

Related Posts Widget with Thumbnails <= 1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Mar 31, 2025Unpatched
Version History

Related Posts Widget with Thumbnails Release Timeline

v1.2Current1 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Related Posts Widget with Thumbnails Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
82
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

4% escaped85 total outputs
Attack Surface

Related Posts Widget with Thumbnails Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_headrelated.php:24
filterwp_headrelated.php:331
actionwidgets_initrelated.php:416
actionadmin_initrelated.php:504
actionadmin_menurelated.php:509
Maintenance & Trust

Related Posts Widget with Thumbnails Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedOct 3, 2023
PHP min version
Downloads18K

Community Trust

Rating74/100
Number of ratings6
Active installs100
Developer Profile

Related Posts Widget with Thumbnails Developer Profile

wp-buy

15 plugins · 345K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
879 days
View full developer profile
Detection Fingerprints

How We Detect Related Posts Widget with Thumbnails

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-css3-related-posts-widget/js/simpletabs_1.3.js/wp-content/plugins/advanced-css3-related-posts-widget/css/simpletabs.css/wp-content/plugins/advanced-css3-related-posts-widget/images/noimage.png
Script Paths
/wp-content/plugins/advanced-css3-related-posts-widget/js/simpletabs_1.3.js

HTML / DOM Fingerprints

CSS Classes
related-posts-widget
FAQ

Frequently Asked Questions about Related Posts Widget with Thumbnails